Need opinion On sessions - Cookies mandatory?

From: Date: Wed, 23 Jan 2002 01:05:15 +0000
Subject: Need opinion On sessions - Cookies mandatory?
Groups: php.general 
Request: Send a blank email to php-general+get-81612@lists.php.net to get a copy of this message
I'm coding a site which will require user authentication, and I'm going to use sessions to do this. Should I make cookies mandatory, or should I use the SID constant (defined if the PHP 4.0 session functions could not set a cookie) and append the session ID to urls in case cookies can't be used. Making cookies mandatory would be less convenient for people who disable cookies, but appending the session ID could be a security risk. Consider this: Someone is viewing a page and says "oh cool, I want Joe to see this". He then copy/pastes the URL, sessionID and all, to Joe, who then loads up the page using his friend's SessionID. With cookies, this would not happen. So basically, I'm asking, is the convenience of not requiring cookies more important than the possible security risk of putting the sessionID in the URL? Secondly, is there a way to avoid this type of situation. Thanks for any responses! =)

« previous php.general (#81612) next »