Re: [PHP4BETA] Session Cookies With External Reference Checking Not Working; Patch Attached
| From: | Sascha Schumann | Date: | Mon, 28 Feb 2000 15:03:42 +0000 |
| Subject: | Re: [PHP4BETA] Session Cookies With External Reference Checking Not Working; Patch Attached | ||
| References: | 1 | Groups: | php.version4 |
| Request: | Send a blank email to php-version4+get-11136@lists.php.net to get a copy of this message | ||
Andreas,
On Mon, Feb 28, 2000 at 09:14:31AM -0500, Andreas Pour wrote:
>
> Hi,
>
> Using cookies with external reference checking is broken. Actually,
> Patch level 1 of PHP4 has all session-cookie checking broken if you set
> session.referer_check to 0 in php.ini, this patch fixes the problem:
You disable session.referer_check by assigning it the empty string.
> It's not clear to me why you are looking at HTTP_REFERER. The relevant
No. REMOTE_ADDR can change (cascaded proxies). referer_check
is there to check HTTP_REFERER. It's useful, if site A points
to site B using an URL which contains a session id. That
sometimes happens, if a user copies the plain URL including
the session id and puts it on his/her homepage. referer_check
will reject the session id then.
Example
Site B is set up this way
session.referer_check = "mysite.com"
Site A has a link to http://mysite.com/?PHPSESSID=foobar
When a user clicks on the link, site B will see the referer
of site A. That referer doesn't include mysite.com, so the
session id foobar is rejected.
--
Regards,
Sascha Schumann
Consultant
Attachment: [application/pgp-signature]
Attachment: [application/pgp-signature]