Re: [PHP4BETA] Docs for sessions?

From: Date: Thu, 22 Jul 1999 11:13:07 +0000
Subject: Re: [PHP4BETA] Docs for sessions?
References: 1 2  Groups: php.version4 
Request: Send a blank email to php-version4+get-2508@lists.php.net to get a copy of this message
On Thu, Jul 22, 1999 at 08:52:12AM +0100, Samuel Liddicott wrote: > > > > -----Original Message----- > > From: Sascha Schumann [mailto:sascha@schumann.cx] > > Sent: 22 July 1999 01:10 > > To: Matthew Clark > > Cc: php4beta@lists.php.net > > Subject: Re: [PHP4BETA] Docs for sessions? > > > > The session module will try to set a cookie on the client side > > and, if it's not completely sure that the cookie was set, defines > > a constant (sid) to contain "<session-name>=<session-id>". > > > > You should read about the security impacts of the so called get > > mode (where you transport session IDs in the URL) in the PHPLIB > > mailing list archive. Cookies have some serious advantages when > > it comes to security (i.e. they are not logged, not transported > > in the HTTP Referer and so on). > > Are you saying if cookies aren't supported it will use get mode? yes > > One alternative is to have the session as part of the leading path > > http://my.domain/session-name=sessionid/index.html > > and let the server internally re-write the URL (without it). ALSO if a page > is requested without a sid, but the referring page was from the same site > with a sid, then a redirect to a URL including the SID is sent. well, that's nice. You can do this with the session module already. > Thus a path-based session ID can be retained even without cookies, as long > as a referer is sent (which most browsers do). Do you have a sample configuration for Apache which shows how to do that? We could add this to the documentation for interested parties. -- Regards, Sascha Schumann Consultant

« previous php.version4 (#2508) next »