in reply to Re: Game.
in thread Game.
For instance, if you set a cookie called 'gold' with value '10' I could edit my cookie file and give myself 1000000 gold.
The proper way to do it is to hand a unique string (such as provided by Apache::Session) to the browser as a cookie. When they return it, load their data from the backing store.
This stops users from tampering with the information.
____________________
Jeremy
I didn't believe in evil until I dated it.
|
|---|
| Replies are listed 'Best First'. | |
|---|---|
|
Re: Session identification (was: Game).
by pmas (Hermit) on Jun 05, 2001 at 21:52 UTC | |
by jepri (Parson) on Jun 06, 2001 at 05:11 UTC | |
by Vynce (Friar) on Jun 06, 2001 at 05:30 UTC | |
by jepri (Parson) on Jun 06, 2001 at 09:06 UTC | |
by Vynce (Friar) on Jun 06, 2001 at 10:51 UTC | |
| |
|
Re: Re: Re: Game.
by Anonymous Monk on Jun 04, 2001 at 16:39 UTC | |
by jepri (Parson) on Jun 04, 2001 at 16:43 UTC |