note 31799 deleted from function.session-id by didou

From: Date: Sun, 18 May 2003 03:41:58 +0000
Subject: note 31799 deleted from function.session-id by didou
References: 1  Groups: php.notes 
Request: Send a blank email to php-notes+get-48387@lists.php.net to get a copy of this message
Note Submitter: gmgiles@pacbell.net ---- Regarding Thomas' note above about using SID as part of the URL; I'd advise against passing the session ID between pages in a URL using header(), as it leaves open the possibility of session stealing. Instead you should use: session_start(); $_SESSION['sess_id'] = session_id(); header("Location:whatever.php"); You can then reference the same session in whatever.php without exposing the session ID, or leaving open the possibility somebody will bookmark a URL with a session ID in it and try to access it later.

« previous php.notes (#48387) next »