Jump to content

[SOLVED] Opinion on security feature


waynew

Recommended Posts

In order to prevent CSRF on certain links, I have in place something like this:

 

<a href="logout.php?sid=<?php echo session_id(); ?>">Logout</a>

 

Then I check to see whether or not the session_id matches the sid in the URL. Is this method pretty safe? I know that SIDs are pretty near impossible to guess.

 

Link to comment
https://forums.phpfreaks.com/topic/178023-solved-opinion-on-security-feature/
Share on other sites

Archived

This topic is now archived and is closed to further replies.

×
×
  • Create New...

Important Information

We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.