in reply to Loging a user out with CGI and Cookies?
In there, I say something like: do not use the presence of a cookie to indicate a logged-in state, because the browser is free to ignore your requests to remove the cookie or expire it after a while.
Instead, simply ignore that particular cookie if it's sent in the future. This means you should use a cookie only as a key to a server-side database which shows the current state of logged-in or not.
-- Randal L. Schwartz, Perl hacker
|
|---|
| Replies are listed 'Best First'. | |
|---|---|
|
Re: Re: Loging a user out with CGI and Cookies?
by LiTinOveWeedle (Scribe) on Apr 17, 2001 at 02:50 UTC | |
by merlyn (Sage) on Apr 17, 2001 at 17:06 UTC | |
|
Re: Re: Loging a user out with CGI and Cookies?
by r.joseph (Hermit) on Apr 16, 2001 at 19:34 UTC | |
by LiTinOveWeedle (Scribe) on Apr 16, 2001 at 21:05 UTC | |
by r.joseph (Hermit) on Apr 17, 2001 at 02:39 UTC |