Re: [PHP4BETA] Docs for sessions?
| From: | Sascha Schumann | Date: | Thu, 22 Jul 1999 11:13:07 +0000 |
| Subject: | Re: [PHP4BETA] Docs for sessions? | ||
| References: | 1 2 | Groups: | php.version4 |
| Request: | Send a blank email to php-version4+get-2508@lists.php.net to get a copy of this message | ||
On Thu, Jul 22, 1999 at 08:52:12AM +0100, Samuel Liddicott wrote:
>
>
> > -----Original Message-----
> > From: Sascha Schumann [mailto:sascha@schumann.cx]
> > Sent: 22 July 1999 01:10
> > To: Matthew Clark
> > Cc: php4beta@lists.php.net
> > Subject: Re: [PHP4BETA] Docs for sessions?
> >
> > The session module will try to set a cookie on the client side
> > and, if it's not completely sure that the cookie was set, defines
> > a constant (sid) to contain "<session-name>=<session-id>".
> >
> > You should read about the security impacts of the so called get
> > mode (where you transport session IDs in the URL) in the PHPLIB
> > mailing list archive. Cookies have some serious advantages when
> > it comes to security (i.e. they are not logged, not transported
> > in the HTTP Referer and so on).
>
> Are you saying if cookies aren't supported it will use get mode?
yes
>
> One alternative is to have the session as part of the leading path
>
> http://my.domain/session-name=sessionid/index.html
>
> and let the server internally re-write the URL (without it). ALSO if a page
> is requested without a sid, but the referring page was from the same site
> with a sid, then a redirect to a URL including the SID is sent.
well, that's nice. You can do this with the session module
already.
> Thus a path-based session ID can be retained even without cookies, as long
> as a referer is sent (which most browsers do).
Do you have a sample configuration for Apache which shows how to
do that? We could add this to the documentation for interested
parties.
--
Regards,
Sascha Schumann
Consultant