Re: [Pmtool-devel] another change
Status: Inactive
Brought to you by:
willuhn
From: Robby R. <ro...@pl...> - 2005-02-20 23:29:25
|
On Sun, 2005-02-20 at 15:21 -0800, Robby Russell wrote: > I'd like to get rid of needing the PHPSESSION in the URL. > > -Robby > Modifying the function encodeUrl() in tool.inc.php seems to resolve this. Is there any need to have this? What I have seen is a customer would send me a link to something they noticed and I'd click on it and it'd be their session. Don't think it should be so easy to hijack someones session. -Robby -- /*************************************** * Robby Russell | Owner.Developer.Geek * PLANET ARGON | www.planetargon.com * Portland, OR | ro...@pl... * 503.351.4730 | blog.planetargon.com * PHP/PostgreSQL Hosting & Development * --- Now hosting Ruby on Rails Apps --- ****************************************/ |