You are right. I used the referer in a "crude" way to determine if my session id is directly called or passed from a script. I was avoiding the possibility of session hijacking or replaying where one simply replay a session_id from the browser history and there he goes... doing stuffs he's not supposed to do.
Though my session id's are set to expire after "n" minutes, is there another sanity check besides using a "trivial" referrer?
In reply to Re: •Re: $ENV{HTTP_REFERER} Problem on a Windows Client
by soon_j
in thread $ENV{HTTP_REFERER} Problem on a Windows Client
by soon_j
| For: | Use: | ||
| & | & | ||
| < | < | ||
| > | > | ||
| [ | [ | ||
| ] | ] |