KnowledgeHub
Questions
Tags
Users
Search
Alex Rivera
|
Logout
Edit Question
Title
Body
I am wondering if this is a secure way to set a token, unless there actually is a token generated, I generate one, and use it throughout the applications and those forms. One token per session? if (!isset($_SESSION['token'])) { $data['token'] = uniqid(rand(), true); session_regenerate_id(); $_SESSION['token'] = $data['token']; } Would it be necessary to clear out the token on a submitted form? or just stay with it, even though I submitted a form?
Tags (comma-separated)
Save Edits
Cancel