note 23712 deleted from function.setcookie by sniper

From: Date: Wed, 11 Dec 2002 07:16:00 +0000
Subject: note 23712 deleted from function.setcookie by sniper
References: 1  Groups: php.notes 
Request: Send a blank email to php-notes+get-40722@lists.php.net to get a copy of this message
Until M$ fixes IIS, there is a nicer work around than prefixing all your pages with 'nph-' and dealing with that headache or setting cookies via javascript: 1) hidden form fields or 2) GET. 1: This means converting all the session links you can into form fields, and including a hidden input tag like: name="iis302fault" value="cookiedata" 2: This is "ugly" and would require appending the data onto the end of hyperlinks like ?iis302fault=cookie%20data If method 2 is used, the cookie data needs to be CGI encoded. Preferably, only a session handle (256-bits -- roughly 40 printable characters -- or larger) would be used with either work around, and the real data would be maintained in a temp file or database server side. If the scripts are installed on mixed HTTP servers (as in IIS and non-IIS), you can check SERVER_SOFTWARE and SERVER_SIGNATURE to determine which HTTP Server the script is installed, then branch to the optimal cookie handling routines.

« previous php.notes (#40722) next »