RE: [PHP4BETA] hidden variables !<form>
| From: | Dan | Date: | Tue, 06 Jun 2000 23:59:07 +0000 |
| Subject: | RE: [PHP4BETA] hidden variables !<form> | ||
| References: | 1 | Groups: | php.version4 |
| Request: | Send a blank email to php-version4+get-16180@lists.php.net to get a copy of this message | ||
There is a reason to use a POST for security reasons - SSL would make them
secure in transit. Yes, you can see the variables, but a GET method would
not allow those variables to be encrypted.
To "auto" POST, add a generic JavaScript "onClick" handler to EVERY link
like this:
<a href='../somedirectory/index.phtml' onClick='return postTo( this )'>
(note: if the page is written in PHP, I like to use a PHP function that will
create the HTML href tag)
Then in JavaScript, postTo() looks like this:
function postTo( link )
{
document.forms[0].action = link.href; // note assumption that
there is just one form!!
document.forms[0].submit(); // off we go
return false; // must return false for
this to work
}
Dan Sevush
CTO Dan's Chocolates
www.danschocolates.com - We donate 5% of your purchase to a good cause that
you select.
> If security is a concern for you then you should only use
> them as a sesion ID at most and back that up with some other
> Identifier. The reason
> is that 'post' method using hidden fields are just as vulnerable to
> manipulation as 'get' method. Fewer people will try it but it all just
> depends on how secure you want it. Storing variables using
> hidden fields
> are still stored by the browser and transmited to the server just as
> cookies are, and thus still subject to end user manipulation.