note 9925 modified in function.session-register by imajes

From: Date: Thu, 31 Jan 2002 05:19:18 +0000
Subject: note 9925 modified in function.session-register by imajes
References: 1  Groups: php.notes 
Request: Send a blank email to php-notes+get-26067@lists.php.net to get a copy of this message
Note that when you first call session_register('var'), the global $var may already contain a value passed in by GET or POST. It is only after you have called session_register('var') that $var references $HTTP_SESSION_VARS['var'] instead (depending of course on your php.ini configuration). So, my advice is to check or clear the value of $var, the first time you call session_register('var') unless you want a user to try 'http://mydomain/index.php?loggedin=true' on your script that contains code like: <?php session_register('loggedin'); if ($loggedin) { //show secure content } else { //show login } ?> I use the following function to set and register session variables with initial values. function session_var_init($var, $val) { if (!session_is_registered($var)) { session_register($var); $GLOBALS[$var] = $val; } } Note that this function calls session_register() and sets $var to an initial value only if $var is not already registered in the session, thus avoiding the potential GET and POST problem described above. <?php session_var_init('loggedin',false); if ($loggedin) { //show secure content } else { //show login } ?> --was-- Note that when you first call session_register('var'), the global $var may already contain a value passed in by GET or POST. It is only after you have called session_register('var') that $var references $HTTP_SESSION_VARS['var'] instead (depending of course on your php.ini configuration). So, my advice is to check or clear the value of $var, the first time you call session_register('var') unless you want a user to try 'http://mydomain/index.php?loggedin=true' on your script that contains code like: &lt;?php session_register('loggedin'); if ($loggedin) { //show secure content } else { //show login } ?> I use the following function to set and register session variables with initial values. function session_var_init($var, $val) { if (!session_is_registered($var)) { session_register($var); $GLOBALS[$var] = $val; } } Note that this function calls session_register() and sets $var to an initial value only if $var is not already registered in the session, thus avoiding the potential GET and POST problem described above. &lt;?php session_var_init('loggedin',false); if ($loggedin) { //show secure content } else { //show login } ?> http://www.php.net/manual/en/function.session-register.php

« previous php.notes (#26067) next »