Re: [PHP4BETA] Docs for sessions?
| From: | Sascha Schumann | Date: | Thu, 22 Jul 1999 02:23:51 +0000 |
| Subject: | Re: [PHP4BETA] Docs for sessions? | ||
| References: | 1 2 | Groups: | php.version4 |
| Request: | Send a blank email to php-version4+get-2487@lists.php.net to get a copy of this message | ||
On Thu, Jul 22, 1999 at 02:50:24AM +0100, Matthew Clark wrote:
> > The session module will try to set a cookie on the client side
> > and, if it's not completely sure that the cookie was set, defines
> > a constant (sid) to contain "<session-name>=<session-id>".
> >
> > You should read about the security impacts of the so called get
> > mode (where you transport session IDs in the URL) in the PHPLIB
> > mailing list archive. Cookies have some serious advantages when
> > it comes to security (i.e. they are not logged, not transported
> > in the HTTP Referer and so on).
>
>
> Ah nooo.. We made the decision with our current project to
> reject users who have no cookie support or cookies switched off
> (and JavaScript 1.1+). We wont paste session IDs in the URL at
> all!!! What I meant was, just store the single sid in a cookie
> and any other relevant data in a server side database...
we do that exactly.
--
Regards,
Sascha Schumann
Consultant