Still celebrating National IT Professionals Day with 3 months of free Premium Membership. Use Code ITDAY17

x
?
Solved

Php get the last url

Posted on 2006-10-31
2
Medium Priority
?
1,353 Views
Last Modified: 2006-11-18
Hey.

Is there a way to get the last url in php.

Example:
I pass data trough a form but i what to make shure that the form post comes from my site and not a other site.
So that the pre url can be validated
0
Comment
Question by:macbox
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
2 Comments
 
LVL 19

Accepted Solution

by:
VoteyDisciple earned 1500 total points
ID: 17842552
The $_SERVER['HTTP_REFERER'] variable will do that.

HOWEVER!  (and it's a big "however") that particular variable comes from the browser's HTTP request.  There's no guarantee it will exist (the browser may not send it), and there's nothing at all to keep a malicious user from faking it.

If you're just hoping to cut down on spam or something of that nature then it may do the trick.  If you're after a real security measure, this isn't it.
0
 
LVL 8

Expert Comment

by:adg080898
ID: 17846032
Is the user logged in? What I mean is, do you have a way to identify the user?

I am going to assume that you have some sort of database record for the user.

I suggest you have a field in your user record that stores a random string. When you generate the form page, generate a long (longer is stronger security, 32 characters is very strong) random string of characters and store that string in their user database record. Also, put a hidden field in the form with the value matching their random string.

Then, where you handle the form submission, compare the hidden field's value to the one generated when the form was displayed.

This way, the only way for the post to work is to know the value of the hidden field. This way, you can verify that the user really used your form.
0

Featured Post

How to Use the Help Bell

Need to boost the visibility of your question for solutions? Use the Experts Exchange Help Bell to confirm priority levels and contact subject-matter experts for question attention.  Check out this how-to article for more information.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Since upgrading to Office 2013 or higher installing the Smart Indenter addin will fail. This article will explain how to install it so it will work regardless of the Office version installed.
We live in a world of interfaces like the one in the title picture. VBA also allows to use interfaces which offers a lot of possibilities. This article describes how to use interfaces in VBA and how to work around their bugs.
In this fifth video of the Xpdf series, we discuss and demonstrate the PDFdetach utility, which is able to list and, more importantly, extract attachments that are embedded in PDF files. It does this via a command line interface, making it suitable …
Starting up a Project

721 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question