sessions and authentication

From: Date: Fri, 21 Dec 2001 09:40:15 +0000
Subject: sessions and authentication
Groups: php.general 
Request: Send a blank email to php-general+get-78436@lists.php.net to get a copy of this message
Hey guys, I know this has been brought up several times but can't find it in the archives of this list. I have some PHP 4 scripts that check the value of a "logged in" variable. if the user authenticates him/her self, then the "logged in" variable gets set and registered with the session. How can I stop some evil person from passing that variable to my script using GET or POST methods ? I tried: $HTTP_POST_VARS[user_authenticated] = ""; $HTTP_GET_VARS[user_authenticated] = ""; and: unset($HTTP_POST_VARS[user_authenticated]); unset($HTTP_GET_VARS[user_authenticated]); but that didn't do me any good. Please advise. Thank you, Steve Maroney

« previous php.general (#78436) next »