Changeset 1853 in ExiteCMS for trunk/includes/session_functions.php
- Timestamp:
- 10/16/08 11:37:18 (4 years ago)
- File:
-
- 1 edited
-
trunk/includes/session_functions.php (modified) (2 diffs)
Legend:
- Unmodified
- Added
- Removed
-
trunk/includes/session_functions.php
r1802 r1853 36 36 // to stay in the same session when uploading file(s) 37 37 // (session hijacking is mitigated by the session_ua function) 38 if (isset($_POST['SWFSESSIONID']) && !empty($_POST['SWFSESSIONID'])) {39 $_COOKIE['site_visited'] = $_POST['SWFSESSIONID'];40 }41 38 if (isset($_POST[$settings['session_name']]) && !empty($_POST[$settings['session_name']])) { 42 39 session_id($_POST[$settings['session_name']]); … … 207 204 208 205 $session_ua = ""; 209 // $session_ua .= isset($_SERVER['HTTP_USER_AGENT']) ? $_SERVER['HTTP_USER_AGENT'] : ""; 210 $session_ua .= isset($_SERVER['REMOTE_ADDR']) ? $_SERVER['REMOTE_ADDR'] : ""; 211 $session_ua .= isset($_SERVER['HTTP_VIA']) ? $_SERVER['HTTP_VIA'] : ""; 212 $session_ua .= isset($_SERVER['HTTP_X_FORWARDED_FOR']) ? $_SERVER['HTTP_X_FORWARDED_FOR'] : ""; 206 207 // when called from SWFUpload, set the session cookies from the post variable 208 // to stay in the same session when uploading file(s) 209 // (session hijacking is mitigated by the session_ua function) 210 if (isset($_POST['SWFSESSIONID']) && !empty($_POST['SWFSESSIONID']) && strlen($_POST['SWFSESSIONID'])==32) { 211 return $_POST['SWFSESSIONID']; 212 } 213 $session_ua .= isset($_SERVER['HTTP_USER_AGENT']) ? $_SERVER['HTTP_USER_AGENT'] : ""; 214 // $session_ua .= isset($_SERVER['REMOTE_ADDR']) ? $_SERVER['REMOTE_ADDR'] : ""; 213 215 $session_ua .= isset($_COOKIE['site_visited']) ? $_COOKIE['site_visited'] : ""; 214 216
Note: See TracChangeset
for help on using the changeset viewer.
