note 32030 added to ref.session
| From: | etonphp at igels dot net | Date: | Wed, 14 May 2003 09:37:33 +0000 |
| Subject: | note 32030 added to ref.session | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-47947@lists.php.net to get a copy of this message | ||
Hi,
this is a comment to the note from jvilla at isdesigndev dot com posted on 26-Apr-2003 03:10.
Everything you save in $_SESSION will be saved on the server, so if I'm not totally wrong all
you do helps nothing. You can check the IP address or the browser
($_SERVER['HTTP_USER_AGENT'] != $_SESSION['browser'] ...), and you should check
if this is an old session (timeout), but if somebody take over a session,
$_SESSION['current_session'] != $_SESSION['session_user'] ."=".
$_SESSION['session_key']) wouldn't notice.
Sorry for my buggy english,
iGEL
--
http://www.php.net/manual/en/ref.session.php
http://master.php.net/manage/user-notes.php?action=edit+32030
http://master.php.net/manage/user-notes.php?action=delete+32030
http://master.php.net/manage/user-notes.php?action=reject+32030