sessions and authentication
| From: | Steve Maroney | Date: | Fri, 21 Dec 2001 09:40:15 +0000 |
| Subject: | sessions and authentication | ||
| Groups: | php.general | ||
| Request: | Send a blank email to php-general+get-78436@lists.php.net to get a copy of this message | ||
Hey guys,
I know this has been brought up several times but can't find it in the
archives of this list.
I have some PHP 4 scripts that check the value of a "logged in" variable.
if the user authenticates him/her self, then the "logged in" variable gets
set and registered with the session. How can I stop some evil person from
passing that variable to my script using GET or POST methods ?
I tried:
$HTTP_POST_VARS[user_authenticated] = "";
$HTTP_GET_VARS[user_authenticated] = "";
and:
unset($HTTP_POST_VARS[user_authenticated]);
unset($HTTP_GET_VARS[user_authenticated]);
but that didn't do me any good. Please advise.
Thank you,
Steve Maroney