Session security

From: Date: Tue, 29 May 2007 17:04:29 +0000
Subject: Session security
Groups: php.internals 
Request: Send a blank email to internals+get-29874@lists.php.net to get a copy of this message
Hi all, Just wanted to get your opinion on a discussion currently going on on the general list. Why does the PHP session extension not use something like the user agent to validate that a session ID has not been hijacked? Or is this something that just hasn't been implemented yet? -Stut

« previous php.internals (#29874) next »