I’m using uploadify and the script (which uses adobe flash) creates a new session instead of using the current one when requesting the upload action url. To fix that I need to pass ahead the session id.
Is there a way to do this without permit session fixation (hijacking)?
Here are some details of the problem:
Sessions and uploadify
Thanks!
Create a temporary upload session in your script (untested, but you get the point about being able to have several different sessions):
So, in your receiving script:
The user will still have 2 cookies, and possibly UPLOADSESSION is fixated, but you don’t use it for anything else then uploading, and only for 1 upload (although you might want to allow more).
Alternatively, you could just call a
session_regenerate_id();on the first request after an upload (just set a flag in the$_SESSIONon upload).