note 25443 rejected from ref.session by nicos
| From: | nicos@php.net | Date: | Tue, 24 Sep 2002 10:02:17 +0000 |
| Subject: | note 25443 rejected from ref.session by nicos | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-37176@lists.php.net to get a copy of this message | ||
From the docs: "Note: Non-relative URLs are assumed to point to external sites and hence
don't append the SID, as it would be a security risk to leak the SID to a different server.
"
Bud what if you WANT to pass the session? Say you are going from your URL to the secure URL
provided by your hosting company.
to link to the new URL
href="https://newurl.com/mypage.php?<?
echo session_name().'='.session_id();?>"
or in a form
action="https://newurl.com/mypage.php?<?
echo session_name().'='.session_id();?>"
Alone this won't work...
At the top of mypage.php you should have something like:
if (isset($_GET[session_name()])) {session_id($_GET[session_name()]);} session_start ();
This will look for the session in the GET vars. If it is there it will use it, if not it will act as
normal. This means that once your user is at the new URL, he can browse the site and return to this
page w/o risk of losing the session.
Basically, now both URLs are using the same session id.