note 44754 added to function.header
| From: | raf at vircan dot zzn dot com | Date: | Sun, 15 Aug 2004 16:22:17 +0000 |
| Subject: | note 44754 added to function.header | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-74708@lists.php.net to get a copy of this message | ||
Small note for using sessions for users with cookies disabled.
When a client does not accept cookies, the sessionID is propagated in the querystring. With a
redirect like
<?php
header('Location: http://'.$_SERVER['HTTP_HOST']
.dirname($_SERVER['PHP_SELF'])
.'/index.php');
die();
?>
your session will be lost. You need to explicitely append the SID here to keep the session going.
Security note: appending the SID should only be done on pages of your own domain, to prevent leaking
of the sessionID and sessionhijacking.
For internal redirects, you can use a function like
<?php
session_start();
/*cookiedisabled-safe redirect to a page in the current directory. cookie 'identif' is
* an arbitraty persistent cookie that you set on the first page (loginpage?) and
* where you can test on to see if cookies are returned. Can be any cookie. */
function http_redirect_current($filename){
if (!isset($_COOKIE['identif'])){
$filename .= '?' . SID;
}
header('Location: http://'.$_SERVER['HTTP_HOST']
.dirname($_SERVER['PHP_SELF'])
.'/' . $filename);
die() ;
}
// which can be used like
if(!$_SESSION['loggedin']){
http_redirect_current('index.php');
}
?>
----
Manual Page -- http://www.php.net/manual/en/function.header.php
Edit -- http://master.php.net/manage/user-notes.php?action=edit+44754
Delete -- http://master.php.net/manage/user-notes.php?action=delete+44754&report=yes
Reject -- http://master.php.net/manage/user-notes.php?action=reject+44754&report=yes
Search -- http://master.php.net/manage/user-notes.php