Re: Cookie semi-security.

From: Date: Wed, 24 Jan 2001 22:07:39 +0000
Subject: Re: Cookie semi-security.
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-36498@lists.php.net to get a copy of this message
Enable track_vars in php's config and use $PHP_COOKIE_VARS['cookie_id'] to get the value of the cookie. --Toby ----- Original Message ----- From: "April" <april@ponymail.com> To: "PHP General" <php-general@lists.php.net> Sent: Wednesday, January 24, 2001 5:06 PM Subject: [PHP] Cookie semi-security. > Stupid question, but I'm stumped. > > I'm passing a persons id through a cookie, then using that to determine if > they're allowed to be doing what they're trying to do (change listings, > etc.). Right now, I'm getting the value of the cookie by just accessing > $cookie_id, without anything fancy. The problem is, if someoen just denies a > cookie and adds ?cookie_id=9 at the end, they might as well be the person > with an id of 9. Is there a way for me to check and be sure that that > value came from a cookie, and not the url bar? > > > -- > PHP General Mailing List (http://www.php.net/) > To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net > For additional commands, e-mail: php-general-help@lists.php.net > To contact the list administrators, e-mail: php-list-admin@lists.php.net > >

« previous php.general (#36498) next »