note 31799 deleted from function.session-id by didou
| From: | didou@php.net | Date: | Sun, 18 May 2003 03:41:58 +0000 |
| Subject: | note 31799 deleted from function.session-id by didou | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-48387@lists.php.net to get a copy of this message | ||
Note Submitter: gmgiles@pacbell.net
----
Regarding Thomas' note above about using SID as part of the URL; I'd advise against
passing the session ID between pages in a URL using header(), as it leaves open the possibility of
session stealing. Instead you should use:
session_start();
$_SESSION['sess_id'] = session_id();
header("Location:whatever.php");
You can then reference the same session in whatever.php without exposing the session ID, or leaving
open the possibility somebody will bookmark a URL with a session ID in it and try to access it
later.