note 31379 deleted from function.setcookie by didou
| From: | didou@php.net | Date: | Sat, 31 May 2003 15:02:28 +0000 |
| Subject: | note 31379 deleted from function.setcookie by didou | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-49494@lists.php.net to get a copy of this message | ||
Note Submitter: serrano@no.emails.pls
----
also another important issue is to check your received cookies and/or escape them before using in
any database query, otherwise you may end up users sending what they want to the database... an
MD5ed session string is easy to check, like this:
ereg ("^[a-zA-Z0-9]{32}$", $cookie)
...