开发者

Is unsetting $_SESSION variable a bad idea before setting session var?

In a page I'm designing, I'm storing data via开发者_运维知识库 $_session but since I'm calling the pages dynamically with jquery I wanted to add some security and unset($_SESSION['var']) before i set them just in case anything would happen. My question is if unsetting session a bad idea before it is set, or is it completely valid?


It's unnecessary and will have no effect.

If you are calling sensitive data through Ajax calls, you need to properly secure it against attacks, just as you would secure a normal page - for example by having a session-based login, and checking whether the current user is logged in!

0

上一篇:

下一篇:

精彩评论

暂无评论...
验证码 换一张
取 消

最新问答

问答排行榜