Justtechjobs.com Find a programming school near you






Online Campus Both


php-general | 2001062

Re: [PHP] Stopping stolen / spoofed / linked sessions From: Rasmus Lerdorf (rasmus <email protected>)
Date: 06/29/01

> I want to use PHP4 sessions for authentication,

Ok, stop right there. Sessions and authentication have nothing to do with
each other. To create a secure authenticated site you should be using
HTTP-based authentication over SSL. Sessions are simply for maintaining
state across http requests and have nothing to do with authentication.

-Rasmus

-- 
PHP General Mailing List (http://www.php.net/)
To unsubscribe, e-mail: php-general-unsubscribe <email protected>
For additional commands, e-mail: php-general-help <email protected>
To contact the list administrators, e-mail: php-list-admin <email protected>