note 31948 deleted from function.header by stone

From: Date: Fri, 09 May 2003 18:54:55 +0000
Subject: note 31948 deleted from function.header by stone
References: 1  Groups: php.notes 
Request: Send a blank email to php-notes+get-47755@lists.php.net to get a copy of this message
If you use header("Location: http://somesite.com"); to redirect a user, be sure you put an exit; command directly afterwards. This is especially important if you are making certain that only authenticated users have access to a particular page. Some browsers (and tools, like curl) do not recognize the Location header redirect and will still display whatever the script returned after blowing right through the redirect. Of course, stopping the script from executing for unauthenticated users is a good idea anyway, since it provide a multitude of opportunities for security holes.

« previous php.notes (#47755) next »