Re: session security issue
| From: | Steve Brett | Date: | Tue, 14 Aug 2001 15:49:20 +0000 |
| Subject: | Re: session security issue | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-62666@lists.php.net to get a copy of this message | ||
what about registering a var called loggedin with the session and then
testing on each script to see if it's set to 1 or something ?
then base the access on that ? that's what i use and then register uid with
the session as well so you can use it througout your site ...
ok you've got me worried now, are there any problems with security doing it
that way ????
Steve
"Christian Dechery" <cdechery@brfree.com.br> wrote in message
news:5.0.0.25.2.20010814084143.027c69e0@pop.brfree.com.br...
> I have pages that uses session for security that looks something like
this:
>
> <?php
> session_start();
>
> if( !isset($uid) )
> {
> include("include/auth.inc.php");
> auth_user();
> }
>
> more code...
> ?>
>
> so $uid tells me if the user is logged on or not...
>
> but what if somebody calls the script directly from the address bar like
> this: http://server/script.php?uid=10
>
> wouldn't this be a security problem?
> ____________________________
> Christian Dechery (lemming)
> http://www.tanamesa.com.br
> Gaita-L Owner / Web Developer
>