RE: [PHP4BETA] hidden variables !<form>
| From: | Baeseman, Cliff | Date: | Wed, 07 Jun 2000 18:43:32 +0000 |
| Subject: | RE: [PHP4BETA] hidden variables !<form> | ||
| Groups: | php.version4 | ||
| Request: | Send a blank email to php-version4+get-16198@lists.php.net to get a copy of this message | ||
I personally use a database to hold named variables in a table. To eliminate
the need for cookies I generate a crypted session id and just pass that in a
hidden field. The crypted session id is used to grab the values back from
the table. I also track the time in seconds since the last read or access of
the variable to enforce a timeout of the session. All access methods of the
class first call a method that deletes all expired session keys.
I guess it would be possible to somehow hijack a sessionID but because of
the encryption and session expiration it would be very diffficult.
Just another way to do it I guess.
Cliff Baeseman
-----Original Message-----
From: Curt Zirzow [mailto:curt@zirzow.org]
Sent: Wednesday, June 07, 2000 6:16 AM
To: Douglas Clifton
Cc: php4beta@lists.php.net
Subject: Re: [PHP4BETA] hidden variables !<form>
>
> that pass several hidden variables through from page to
> page w/o using forms or cookies.
hmm... It seems you've eliminated all the ways http protocol
passes data :)
But... check out the session handling functions provided by
php. That is probably the easiest solution.
curt
--
Any time things appear to be going better, you have overlooked
something.
--
PHP 4.0 Beta Mailing List <http://www.php.net/version4/>
To unsubscribe, e-mail: php4beta-unsubscribe@lists.php.net
For additional commands, e-mail: php4beta-help@lists.php.net
To contact the list administrators, e-mail: php4beta-admin@lists.php.net