Originally Posted by SD
maybe.. since the cookie path you probably have is '/' ?

add a 2 letter cookie prefix ( i recommended this in another thread for general security practices anyway ) to each forum..

that forces a logout ( 1 time ), but makes them entirely unique wink


So if I am reading this right, we can leave the path as '/' but we should change the prefix, right. I have upgrade the testing site first and was having a problem with login taking me to a database error only viewable by admin, but if I click back and then on forum list I was logged in.. Changed the prefix and relogged in and no error.


Ian
http://www.firstgenmc.com/ubbthreads

"Experience is a hard teacher because she gives the test first, the lesson afterwords."