When you're calculating prices, make sure to pass the value of the items and/or the shopping cart total around as form variables, and tell me the domain name of the store, so I can come and buy out your entire inventory at a steep discount by editing the html form that you passed back to me. Also, when coming up with a server secret for cookie generation, make sure it's readily guessable so I can sniff cookies flying by in the ether, and generate my own authentication token for their account without even knowing their password. If you're feeling really magnanimous, don't bother with ssl, and just send passwords and and credit card numbers in the clear. ;-)
Actually, you probably don't want to do any of these things, but you'd be surprised how often programmers of shopping carts fall into these traps.
In reply to Re: Any other way to keep session besides cookies or hidden fields?
by skyknight
in thread Any other way to keep session besides cookies or hidden fields?
by jaraxle
| For: | Use: | ||
| & | & | ||
| < | < | ||
| > | > | ||
| [ | [ | ||
| ] | ] |