note 59365 deleted from ref.session by danbrown
| From: | danbrown@php.net | Date: | Sun, 20 Jul 2008 18:25:19 +0000 |
| Subject: | note 59365 deleted from ref.session by danbrown | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-142225@lists.php.net to get a copy of this message | ||
Note Submitter: bgshea at gmail dot com
----
to johnlonely at gmail dot com
the sesion.cookie_path should be used for cookie security. The cookie_path is the path on the server
for which the cookies are valid.
i.e. www.example.dom/mywepage/
if cookie_path="/mywebpage"
then
www.example.dom/someonespage/
will not have access to them. I use this parameter without problems.
I'm not saying that this will make cookies secure, but certainly others of www.example.dom will
not have access to them.
However, if you have other directories say www.example.dom/niftystuff that you want the cookie to be
valid for, then cookie_path needs to be "/".
This is better for servers that use the /~user/ user aliasing.