Session Variables

From: Date: Wed, 25 Jul 2001 20:42:34 +0000
Subject: Session Variables
Groups: php.general 
Request: Send a blank email to php-general+get-59607@lists.php.net to get a copy of this message
Is there anyway to prevent session variables from being overwritten by a get string? I'm wanting to use sessions for security/login, but I'm finding that I can bypass this very easily. For example, I want to hide menu items based on security level, so I use something like this: if ($HTTP_SESSION_VARS["sess_auth"] > 2) { print "<BR><A HREF=/control/newsed.php>News Editor"; }; which works, however, it can be bypassed if someone just enters the value in the url like so: http://secured.site.com/index.php?sess_auth=admin is there any way around this using sessions? Is there a far more suitable method? Thanks! Jason Bell

« previous php.general (#59607) next »