Re: sessions and authentication
| From: | Chris Lee | Date: | Fri, 21 Dec 2001 16:06:28 +0000 |
| Subject: | Re: sessions and authentication | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-78481@lists.php.net to get a copy of this message | ||
insted of
if ( $isloggedin )
user logged in
do
if ( $HTTP_SESSION_VARS['isloggedin'] )
user is logged in
--
Chris Lee
lee@mediawaveonline.com
"Steve Maroney" <steve@stevenet.dhs.org> wrote in message
news:Pine.LNX.4.33.0112210326580.25131-100000@ntsucks.stevenet.dhs.org...
>
>
> Hey guys,
>
> I know this has been brought up several times but can't find it in the
> archives of this list.
>
> I have some PHP 4 scripts that check the value of a "logged in" variable.
> if the user authenticates him/her self, then the "logged in" variable gets
> set and registered with the session. How can I stop some evil person from
> passing that variable to my script using GET or POST methods ?
>
> I tried:
> $HTTP_POST_VARS[user_authenticated] = "";
> $HTTP_GET_VARS[user_authenticated] = "";
>
> and:
> unset($HTTP_POST_VARS[user_authenticated]);
> unset($HTTP_GET_VARS[user_authenticated]);
>
> but that didn't do me any good. Please advise.
>
> Thank you,
> Steve Maroney
>
>
>
>