Re: [PHP4BETA] Docs for sessions?

From: Date: Thu, 22 Jul 1999 02:23:51 +0000
Subject: Re: [PHP4BETA] Docs for sessions?
References: 1 2  Groups: php.version4 
Request: Send a blank email to php-version4+get-2487@lists.php.net to get a copy of this message
On Thu, Jul 22, 1999 at 02:50:24AM +0100, Matthew Clark wrote: > > The session module will try to set a cookie on the client side > > and, if it's not completely sure that the cookie was set, defines > > a constant (sid) to contain "<session-name>=<session-id>". > > > > You should read about the security impacts of the so called get > > mode (where you transport session IDs in the URL) in the PHPLIB > > mailing list archive. Cookies have some serious advantages when > > it comes to security (i.e. they are not logged, not transported > > in the HTTP Referer and so on). > > > Ah nooo.. We made the decision with our current project to > reject users who have no cookie support or cookies switched off > (and JavaScript 1.1+). We wont paste session IDs in the URL at > all!!! What I meant was, just store the single sid in a cookie > and any other relevant data in a server side database... we do that exactly. -- Regards, Sascha Schumann Consultant

« previous php.version4 (#2487) next »