Reply to Re: Authentication with sessions...

Your name:

Reply:


Posted by Gordon Burditt on 11/11/58 11:19

>> Session IDs are normally stored in cookies. A cookie in the XYZ
>> domain shouldn't be passed to you in the DEF domain. However, you
>> can't count on users not manually inserting cookies into their
>> browsers.
>
>I didn't make it clear: other users are able to post websites on our
>intranet server (in other directories, of course). Thus they would be
>writing cookies on the same domain.

So maybe you should get your own domain for this purpose. A subdomain
of your current domain might work (e.g. www2.mydomain.com). Since
you've only got one webserver, you're stuck with that, but Apache
does virtualhosting nicely. I don't recall the rules about passing
cookies between parent domains and subdomains.

Gordon L. Burditt

[Back to original message]


Удаленная работа для программистов  •  Как заработать на Google AdSense  •  England, UK  •  статьи на английском  •  PHP MySQL CMS Apache Oscommerce  •  Online Business Knowledge Base  •  DVD MP3 AVI MP4 players codecs conversion help
Home  •  Search  •  Site Map  •  Set as Homepage  •  Add to Favourites

Copyright © 2005-2006 Powered by Custom PHP Programming

Сайт изготовлен в Студии Валентина Петручека
изготовление и поддержка веб-сайтов, разработка программного обеспечения, поисковая оптимизация