Re: [PHP4BETA] Session Cookies With External Reference Checking Not Working; Patch Attached

From: Date: Mon, 28 Feb 2000 15:03:42 +0000
Subject: Re: [PHP4BETA] Session Cookies With External Reference Checking Not Working; Patch Attached
References: 1  Groups: php.version4 
Request: Send a blank email to php-version4+get-11136@lists.php.net to get a copy of this message
Andreas, On Mon, Feb 28, 2000 at 09:14:31AM -0500, Andreas Pour wrote: > > Hi, > > Using cookies with external reference checking is broken. Actually, > Patch level 1 of PHP4 has all session-cookie checking broken if you set > session.referer_check to 0 in php.ini, this patch fixes the problem: You disable session.referer_check by assigning it the empty string. > It's not clear to me why you are looking at HTTP_REFERER. The relevant No. REMOTE_ADDR can change (cascaded proxies). referer_check is there to check HTTP_REFERER. It's useful, if site A points to site B using an URL which contains a session id. That sometimes happens, if a user copies the plain URL including the session id and puts it on his/her homepage. referer_check will reject the session id then. Example Site B is set up this way session.referer_check = "mysite.com" Site A has a link to http://mysite.com/?PHPSESSID=foobar When a user clicks on the link, site B will see the referer of site A. That referer doesn't include mysite.com, so the session id foobar is rejected. -- Regards, Sascha Schumann Consultant

Attachment: [application/pgp-signature]
« previous php.version4 (#11136) next »