That would mean, even if your PHP that does the checking was able to get
the paramaters passed through the image url...
************
I'll stress this. I haven't experimented much with .htaccess beyond
basic access control so I'm not really sure how that redirect works and
what is being passed to your php script that checks the session flag
variable and what isn't.