note 44754 added to function.header

From: Date: Sun, 15 Aug 2004 16:22:17 +0000
Subject: note 44754 added to function.header
Groups: php.notes 
Request: Send a blank email to php-notes+get-74708@lists.php.net to get a copy of this message
Small note for using sessions for users with cookies disabled. When a client does not accept cookies, the sessionID is propagated in the querystring. With a redirect like <?php header('Location: http://'.$_SERVER['HTTP_HOST'] .dirname($_SERVER['PHP_SELF']) .'/index.php'); die(); ?> your session will be lost. You need to explicitely append the SID here to keep the session going. Security note: appending the SID should only be done on pages of your own domain, to prevent leaking of the sessionID and sessionhijacking. For internal redirects, you can use a function like <?php session_start(); /*cookiedisabled-safe redirect to a page in the current directory. cookie 'identif' is * an arbitraty persistent cookie that you set on the first page (loginpage?) and * where you can test on to see if cookies are returned. Can be any cookie. */ function http_redirect_current($filename){ if (!isset($_COOKIE['identif'])){ $filename .= '?' . SID; } header('Location: http://'.$_SERVER['HTTP_HOST'] .dirname($_SERVER['PHP_SELF']) .'/' . $filename); die() ; } // which can be used like if(!$_SESSION['loggedin']){ http_redirect_current('index.php'); } ?> ---- Manual Page -- http://www.php.net/manual/en/function.header.php Edit -- http://master.php.net/manage/user-notes.php?action=edit+44754 Delete -- http://master.php.net/manage/user-notes.php?action=delete+44754&report=yes Reject -- http://master.php.net/manage/user-notes.php?action=reject+44754&report=yes Search -- http://master.php.net/manage/user-notes.php

« previous php.notes (#74708) next »