note 59365 added to ref.session

From: Date: Sun, 04 Dec 2005 21:18:55 +0000
Subject: note 59365 added to ref.session
Groups: php.notes 
Request: Send a blank email to php-notes+get-99561@lists.php.net to get a copy of this message
to johnlonely at gmail dot com the sesion.cookie_path should be used for cookie security. The cookie_path is the path on the server for which the cookies are valid. i.e. www.example.dom/mywepage/ if cookie_path="/mywebpage" then www.example.dom/someonespage/ will not have access to them. I use this parameter without problems. I'm not saying that this will make cookies secure, but certainly others of www.example.dom will not have access to them. However, if you have other directories say www.example.dom/niftystuff that you want the cookie to be valid for, then cookie_path needs to be "/". This is better for servers that use the /~user/ user aliasing. ---- Manual Page -- http://www.php.net/manual/en/ref.session.php Edit -- http://master.php.net/manage/user-notes.php?action=edit+59365 Delete: added to the manual -- http://master.php.net/manage/user-notes.php?action=delete+59365&report=yes&reason=added+to+the+manual Delete: bad code -- http://master.php.net/manage/user-notes.php?action=delete+59365&report=yes&reason=bad+code Delete: spam -- http://master.php.net/manage/user-notes.php?action=delete+59365&report=yes&reason=spam Delete: useless -- http://master.php.net/manage/user-notes.php?action=delete+59365&report=yes&reason=useless Delete: non-english -- http://master.php.net/manage/user-notes.php?action=delete+59365&report=yes&reason=non-english Delete: already in docs -- http://master.php.net/manage/user-notes.php?action=delete+59365&report=yes&reason=already+in+docs Delete: other reasons -- http://master.php.net/manage/user-notes.php?action=delete+59365&report=yes Reject -- http://master.php.net/manage/user-notes.php?action=reject+59365&report=yes Search -- http://master.php.net/manage/user-notes.php

« previous php.notes (#99561) next »