Re: secure form handling

From: Date: Thu, 07 Feb 2002 04:08:43 +0000
Subject: Re: secure form handling
References: 1 2 3 4  Groups: php.general 
Request: Send a blank email to php-general+get-83807@lists.php.net to get a copy of this message
On Wed, 2002-02-06 at 20:03, Lars Torben Wilson wrote: > On Wed, 2002-02-06 at 19:35, obo wrote: > > sorry lars. i accidentally just emailed you back instead of posting this. > > > > i want the user to be able to see the amount being charged on the screen, but > > not to be able > > to view it in a hidden field in the source code. most shopping cart > > applications are like this. > > > > ?? > > I cannot think of why this would be useful--in fact, if you're having to > chase the same value around in two or more places, you could have a > problem keeping them synced--but hey. :) You could always just store it > in a session variable, which I believe is the way it's normally done. > > > Torben Never mind, I just figured out what you meant. :) Well, in order to prevent it from going client-side (anything sent to the client can be read by the user, one way or another), you'll need to store it server-side. Keep it in a session variable, as I said before. Torben -- Torben Wilson <torben@php.net> http://www.thebuttlesschaps.com http://www.hybrid17.com http://www.inflatableeye.com +1.604.709.0506

« previous php.general (#83807) next »