Need opinion On sessions - Cookies mandatory?
| From: | SpamSucks86 | Date: | Wed, 23 Jan 2002 01:05:15 +0000 |
| Subject: | Need opinion On sessions - Cookies mandatory? | ||
| Groups: | php.general | ||
| Request: | Send a blank email to php-general+get-81612@lists.php.net to get a copy of this message | ||
I'm coding a site which will require user authentication, and I'm going
to use sessions to do this. Should I make cookies mandatory, or should I
use the SID constant (defined if the PHP 4.0 session functions could not
set a cookie) and append the session ID to urls in case cookies can't be
used. Making cookies mandatory would be less convenient for people who
disable cookies, but appending the session ID could be a security risk.
Consider this: Someone is viewing a page and says "oh cool, I want Joe
to see this". He then copy/pastes the URL, sessionID and all, to Joe,
who then loads up the page using his friend's SessionID. With cookies,
this would not happen.
So basically, I'm asking, is the convenience of not requiring cookies
more important than the possible security risk of putting the sessionID
in the URL? Secondly, is there a way to avoid this type of situation.
Thanks for any responses! =)