Re: session security issue

From: Date: Tue, 14 Aug 2001 11:59:32 +0000
Subject: Re: session security issue
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-62617@lists.php.net to get a copy of this message
If you test $HTTP_SESSION_VARS["uid"] instead, you'll know that it came from a session and not from a GET variable. - Tim On 14 Aug 2001 08:42:22 -0300, Christian Dechery wrote: > I have pages that uses session for security that looks something like this: > > <?php > session_start(); > > if( !isset($uid) ) > { > include("include/auth.inc.php"); > auth_user(); > } > > more code... > ?> > > so $uid tells me if the user is logged on or not... > > but what if somebody calls the script directly from the address bar like > this: http://server/script.php?uid=10

« previous php.general (#62617) next »