in reply to The sound of one cookie (not) authenticating
How about hashing into the sessionid parameter that might be in the URL or hidden fields, not only the time (so that you can time out the session), an internal reference to the shopping cart id you store on site, but some indicator of the page that the user clicked from? You can then check the validity of the sessionid against the HTTP_REFERER field, and reissue the sessionid for the new page for all needed links. A user coming from off site with a session id will have practically nothing set in the HTTP_REFERER field, and so you can redirect him to your front page, or if properly encoded, the product field embedded in the sessionid.
I'm not sure how well this would work with proxies or other aspects, but it shouldn't require any access to apache itself...
|
|---|
| Replies are listed 'Best First'. | |
|---|---|
|
Re: Re: The sound of one cookie (not) authenticating
by Hero Zzyzzx (Curate) on Apr 03, 2001 at 19:38 UTC | |
by Masem (Monsignor) on Apr 03, 2001 at 19:52 UTC |