Session Variable Security
| From: | Morty McFly | Date: | Tue, 04 Jul 2000 05:09:20 +0000 |
| Subject: | Session Variable Security | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-4683@lists.php.net to get a copy of this message | ||
I read somewhere that you cannot directly change the value of a registered
session variable using POST or GET- for *very important security reasons*.
And that these must be explicitly reassigned values.
Could anyone elaborate as to what these *very important security reasons*
might be?
-Morty