Welcome Guest, Not a member yet? Register   Sign In
Should session data be handled in the view?
#3

[eluser]Unknown[/eluser]
That makes sense, thanks for the help skunbad.

Another question:
I currently have a secure session that is saved on the database, is it safe to store a boolean stating if the user is an admin or not? I have little experience with this sort of thing so do not know if it would be easy for an attacker to change the boolean within that session to say that they are an admin or it's near impossible for them to do so.

Cheers.


Messages In This Thread
Should session data be handled in the view? - by El Forum - 07-06-2012, 06:14 AM
Should session data be handled in the view? - by El Forum - 07-06-2012, 08:13 AM
Should session data be handled in the view? - by El Forum - 07-06-2012, 09:23 AM
Should session data be handled in the view? - by El Forum - 07-06-2012, 09:32 AM
Should session data be handled in the view? - by El Forum - 07-06-2012, 01:30 PM



Theme © iAndrew 2016 - Forum software by © MyBB