note 8069 added to Session handling functions

From: Date: Fri, 25 Aug 2000 23:58:53 +0000
Subject: note 8069 added to Session handling functions
Groups: php.notes 
Request: Send a blank email to php-notes+get-3266@lists.php.net to get a copy of this message
It would be nice if the documentation said a little bit more about what PHP session functions do behind the scenes. Those of us who want to know how secure session variables are need to know a bit more about this. In particular, I need to know if session data is stored both on the client *and* the server for every session. Also, how is the data integrity verified for sessions? That is, does PHP check to make sure that the values that are in the client-side session variables have not been changed (by a malicious user altering cookies or query strings)? As it stands, I will have to do my own data integrity checking on every session page. Dean. http://www.php.net/manual/ref.session.php

« previous php.notes (#3266) next »