note 59365 added to ref.session
| From: | bgshea at gmail dot com | Date: | Sun, 04 Dec 2005 21:18:55 +0000 |
| Subject: | note 59365 added to ref.session | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-99561@lists.php.net to get a copy of this message | ||
to johnlonely at gmail dot com
the sesion.cookie_path should be used for cookie security. The cookie_path is the path on the server
for which the cookies are valid.
i.e. www.example.dom/mywepage/
if cookie_path="/mywebpage"
then
www.example.dom/someonespage/
will not have access to them. I use this parameter without problems.
I'm not saying that this will make cookies secure, but certainly others of www.example.dom will
not have access to them.
However, if you have other directories say www.example.dom/niftystuff that you want the cookie to be
valid for, then cookie_path needs to be "/".
This is better for servers that use the /~user/ user aliasing.
----
Manual Page -- http://www.php.net/manual/en/ref.session.php
Edit -- http://master.php.net/manage/user-notes.php?action=edit+59365
Delete: added to the manual -- http://master.php.net/manage/user-notes.php?action=delete+59365&report=yes&reason=added+to+the+manual
Delete: bad code -- http://master.php.net/manage/user-notes.php?action=delete+59365&report=yes&reason=bad+code
Delete: spam -- http://master.php.net/manage/user-notes.php?action=delete+59365&report=yes&reason=spam
Delete: useless -- http://master.php.net/manage/user-notes.php?action=delete+59365&report=yes&reason=useless
Delete: non-english -- http://master.php.net/manage/user-notes.php?action=delete+59365&report=yes&reason=non-english
Delete: already in docs -- http://master.php.net/manage/user-notes.php?action=delete+59365&report=yes&reason=already+in+docs
Delete: other reasons -- http://master.php.net/manage/user-notes.php?action=delete+59365&report=yes
Reject -- http://master.php.net/manage/user-notes.php?action=reject+59365&report=yes
Search -- http://master.php.net/manage/user-notes.php