note 31948 deleted from function.header by stone
| From: | stone@php.net | Date: | Fri, 09 May 2003 18:54:55 +0000 |
| Subject: | note 31948 deleted from function.header by stone | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-47755@lists.php.net to get a copy of this message | ||
If you use
header("Location: http://somesite.com");
to redirect a user, be sure you put an
exit;
command directly afterwards.
This is especially important if you are making certain that only authenticated users have access to
a particular page.
Some browsers (and tools, like curl) do not recognize the Location header redirect and will still
display whatever the script returned after blowing right through the redirect.
Of course, stopping the script from executing for unauthenticated users is a good idea anyway, since
it provide a multitude of opportunities for security holes.