Re: sessions and cookies

From: Date: Sat, 31 Mar 2001 21:33:26 +0000
Subject: Re: sessions and cookies
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-46470@lists.php.net to get a copy of this message
I don't recommend putting the Session ID in the URL. Subscibed members could pass URL's to eachother and that way they could have eachother's settings. ""David Hynes"" <david@fed202.com> wrote in message news:NEBBKPMCELLJJBPCHMGPCEIECBAA.david@fed202.com... > I am using sessions to password protect a section of a website. > > I am storing the session ID in a cookie but just in case cookies are not > enabled, I am also passing the session ID in the query string to each page > in the protected directory. > > Please can someone tell me if this could cause any problems, especially if > the user if tries to access a URL from their history bar in the browser with > an old session ID. > > i think what I'm trying to ask is , if the script receives a session ID from > a query string and cookie, which does it use ? > > Thanks, > David. > > ----------------------- > Fed202 Solutions > www.fed202solutions.com > Mobile : 07779 293368 > ----------------------- > > > -- > PHP General Mailing List (http://www.php.net/) > To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net > For additional commands, e-mail: php-general-help@lists.php.net > To contact the list administrators, e-mail: php-list-admin@lists.php.net >

« previous php.general (#46470) next »