in reply to rechecking the cookie

I do not think there is a way to do this..cookies are negotiated when http headers are sent out and there's no other way to access them. In addition, the http protocol doesn't have any way to determine if the user accepted the cookie or not.

So if you really want to know if they rejected your cookie (and remember, it may not be the user directly that rejected it but proxy software upstream), you can store the cookie that you sent them with some identifying info, and then doublecheck against that info when they re-identify to the site; if you don't get a cookie back from them, you can say something to that effect.

But otherwise, either you tell the user that they need to enable cookies to proceed, or work out some other way of authenication for the site when cookies fail (such as authorization codes).


Dr. Michael K. Neylon - mneylon-pm@masemware.com || "You've left the lens cap of your mind on again, Pinky" - The Brain