douhuang75397 2016-10-29 14:21 采纳率: 0%
浏览 398
已采纳

阻止NoRedirect的可能方法

is there any possible way to block or reject the NoRedirect from redirecting your site to index?

because I have this php code checking if the user is logged in

if(!isset($_SESSION['user'])){
    header('Location: index.php');
}

but the problem is, if the hacker blocked the redirect link of my site then he/she can access the pages even he/she didn't login to the site.

Any possible way to prevent this?

  • 写回答

1条回答 默认 最新

  • dqayok7935 2016-10-30 10:33
    关注

    You can end execution of your php code after sending the Location header. For example:

    if(!isset($_SESSION['user'])){
        header('Location: index.php');
        die();
    }
    

    If the hacker blocks the redirect then he will see a blank page.

    本回答被题主选为最佳回答 , 对您是否有帮助呢?
    评论

报告相同问题?

悬赏问题

  • ¥15 C++ 头文件/宏冲突问题解决
  • ¥15 用comsol模拟大气湍流通过底部加热(温度不同)的腔体
  • ¥50 安卓adb backup备份子用户应用数据失败
  • ¥20 有人能用聚类分析帮我分析一下文本内容嘛
  • ¥15 请问Lammps做复合材料拉伸模拟,应力应变曲线问题
  • ¥30 python代码,帮调试
  • ¥15 #MATLAB仿真#车辆换道路径规划
  • ¥15 java 操作 elasticsearch 8.1 实现 索引的重建
  • ¥15 数据可视化Python
  • ¥15 要给毕业设计添加扫码登录的功能!!有偿