note 25443 rejected from ref.session by nicos

From: Date: Tue, 24 Sep 2002 10:02:17 +0000
Subject: note 25443 rejected from ref.session by nicos
References: 1  Groups: php.notes 
Request: Send a blank email to php-notes+get-37176@lists.php.net to get a copy of this message
From the docs: "Note: Non-relative URLs are assumed to point to external sites and hence don't append the SID, as it would be a security risk to leak the SID to a different server. " Bud what if you WANT to pass the session? Say you are going from your URL to the secure URL provided by your hosting company. to link to the new URL href="https://newurl.com/mypage.php?<? echo session_name().'='.session_id();?>" or in a form action="https://newurl.com/mypage.php?<? echo session_name().'='.session_id();?>" Alone this won't work... At the top of mypage.php you should have something like: if (isset($_GET[session_name()])) {session_id($_GET[session_name()]);} session_start (); This will look for the session in the GET vars. If it is there it will use it, if not it will act as normal. This means that once your user is at the new URL, he can browse the site and return to this page w/o risk of losing the session. Basically, now both URLs are using the same session id.

« previous php.notes (#37176) next »