note 59110 added to ref.session
| From: | djhoma at gmail dot com | Date: | Sat, 26 Nov 2005 11:39:10 +0000 |
| Subject: | note 59110 added to ref.session | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-99145@lists.php.net to get a copy of this message | ||
As the reference mentions the value of the register_globals variable can cause some problem if you
use sessions for verification.
If GET variables are registered as global and you check whether the user is already logged in like
this:
<?php
if ($_REQUEST['password'] == "right_password") {
$password = true;
session_register('password');
}
//...later on:
if ($password) {
//secure content
}
?>
Notice, that if you guess the name of the verification variable and pass it through the URL
(index.php?password=true) and the register_globals is true then a script like this lets you in.
I know this is a stupid mistake, but maybe I am not the only one who made it...
So after you registered the $password var, you should check the login with session_is_registered()
function:
<?php
if (session_is_registered('password')) {
//secure content
}
?>
This function cannot be fooled by GET or POST variables...
Hope it's a useful note!
----
Manual Page -- http://www.php.net/manual/en/ref.session.php
Edit -- http://master.php.net/manage/user-notes.php?action=edit+59110
Delete: added to the manual -- http://master.php.net/manage/user-notes.php?action=delete+59110&report=yes&reason=added+to+the+manual
Delete: bad code -- http://master.php.net/manage/user-notes.php?action=delete+59110&report=yes&reason=bad+code
Delete: spam -- http://master.php.net/manage/user-notes.php?action=delete+59110&report=yes&reason=spam
Delete: useless -- http://master.php.net/manage/user-notes.php?action=delete+59110&report=yes&reason=useless
Delete: non-english -- http://master.php.net/manage/user-notes.php?action=delete+59110&report=yes&reason=non-english
Delete: already in docs -- http://master.php.net/manage/user-notes.php?action=delete+59110&report=yes&reason=already+in+docs
Delete: other reasons -- http://master.php.net/manage/user-notes.php?action=delete+59110&report=yes
Reject -- http://master.php.net/manage/user-notes.php?action=reject+59110&report=yes
Search -- http://master.php.net/manage/user-notes.php