Re: Cookie semi-security.
| From: | Toby Butzon | Date: | Wed, 24 Jan 2001 22:07:39 +0000 |
| Subject: | Re: Cookie semi-security. | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-36498@lists.php.net to get a copy of this message | ||
Enable track_vars in php's config and use
$PHP_COOKIE_VARS['cookie_id'] to get the value of the
cookie.
--Toby
----- Original Message -----
From: "April" <april@ponymail.com>
To: "PHP General" <php-general@lists.php.net>
Sent: Wednesday, January 24, 2001 5:06 PM
Subject: [PHP] Cookie semi-security.
> Stupid question, but I'm stumped.
>
> I'm passing a persons id through a cookie, then using that
to determine if
> they're allowed to be doing what they're trying to do
(change listings,
> etc.). Right now, I'm getting the value of the cookie by
just accessing
> $cookie_id, without anything fancy. The problem is, if
someoen just denies a
> cookie and adds ?cookie_id=9 at the end, they might as
well be the person
> with an id of 9. Is there a way for me to check and be
sure that that
> value came from a cookie, and not the url bar?
>
>
> --
> PHP General Mailing List (http://www.php.net/)
> To unsubscribe, e-mail:
php-general-unsubscribe@lists.php.net
> For additional commands, e-mail:
php-general-help@lists.php.net
> To contact the list administrators, e-mail:
php-list-admin@lists.php.net
>
>