nlopess Tue Feb 7 16:54:21 2006 UTC
Modified files: /phpdoc/en/reference/session ini.xml Log: fix #36279: multiple default values for use_only_cookies http://cvs.php.net/viewcvs.cgi/phpdoc/en/reference/session/ini.xml?r1=1.39&r2=1.40&diff_format=u Index: phpdoc/en/reference/session/ini.xml diff -u phpdoc/en/reference/session/ini.xml:1.39 phpdoc/en/reference/session/ini.xml:1.40 --- phpdoc/en/reference/session/ini.xml:1.39 Mon Dec 26 12:12:12 2005 +++ phpdoc/en/reference/session/ini.xml Tue Feb 7 16:54:21 2006 @@ -1,5 +1,5 @@ <?xml version="1.0" encoding="iso-8859-1"?> -<!-- $Revision: 1.39 $ --> +<!-- $Revision: 1.40 $ --> <section id="session.configuration"> &reftitle.runtime; &extension.runtime; @@ -435,8 +435,7 @@ <simpara> <literal>session.use_only_cookies</literal> specifies whether the module will <emphasis role="strong">only</emphasis> use - cookies to store the session id on the client side. Defaults - to <literal>0</literal> (disabled, for backward compatibility). + cookies to store the session id on the client side. Enabling this setting prevents attacks involved passing session ids in URLs. This setting was added in PHP 4.3.0. </simpara>