Re: Session Variables
| From: | Jason Bell | Date: | Wed, 25 Jul 2001 22:05:34 +0000 |
| Subject: | Re: Session Variables | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-59630@lists.php.net to get a copy of this message | ||
Thanks! I changed my code to the following and it plugged that hole. :)
if (!$PHPSESSID) {
$sess_auth = "";
session_register('sess_auth');
}
----- Original Message -----
From: "Sascha Schumann" <sascha@schumann.cx>
To: "Johnson, Kirk" <kjohnson@zootweb.com>
Cc: "PHP Users" <php-general@lists.php.net>
Sent: Wednesday, July 25, 2001 2:10 PM
Subject: RE: [PHP] Session Variables
> On Wed, 25 Jul 2001, Johnson, Kirk wrote:
>
> > > Is there anyway to prevent session variables from being
> > > overwritten by a get string?
> >
> > PHP will do this automatically *if* you initialize your session
variables to
> > *anything* as soon as you register them. For example,
> >
> > session_register("sess_auth");
> > $sess_auth = "";
>
> Note that session_register() will implicitly commence the
> session, and thus will automatically instantiate all session
> variables. Hence, the above two lines need to be reversed,
> otherwise you might overwrite the session variable.
>
> - Sascha Experience IRCG
> http://schumann.cx/
> http://schumann.cx/ircg
>
>
> --
> PHP General Mailing List (http://www.php.net/)
> To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net
> For additional commands, e-mail: php-general-help@lists.php.net
> To contact the list administrators, e-mail: php-list-admin@lists.php.net
>
>