Re: sessions and authentication

From: Date: Fri, 21 Dec 2001 16:06:28 +0000
Subject: Re: sessions and authentication
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-78481@lists.php.net to get a copy of this message
insted of if ( $isloggedin ) user logged in do if ( $HTTP_SESSION_VARS['isloggedin'] ) user is logged in -- Chris Lee lee@mediawaveonline.com "Steve Maroney" <steve@stevenet.dhs.org> wrote in message news:Pine.LNX.4.33.0112210326580.25131-100000@ntsucks.stevenet.dhs.org... > > > Hey guys, > > I know this has been brought up several times but can't find it in the > archives of this list. > > I have some PHP 4 scripts that check the value of a "logged in" variable. > if the user authenticates him/her self, then the "logged in" variable gets > set and registered with the session. How can I stop some evil person from > passing that variable to my script using GET or POST methods ? > > I tried: > $HTTP_POST_VARS[user_authenticated] = ""; > $HTTP_GET_VARS[user_authenticated] = ""; > > and: > unset($HTTP_POST_VARS[user_authenticated]); > unset($HTTP_GET_VARS[user_authenticated]); > > but that didn't do me any good. Please advise. > > Thank you, > Steve Maroney > > > >

« previous php.general (#78481) next »