← PHP for real applications
06 / 8 · 23 MIN

HTTP, sessions, and per-resource authorization

Protect actions and objects, not only the sign-in page.

Understand the concept

Authenticating a session identifies the user, but every operation still needs authorization. A URL ID does not prove ownership. Query or verify resources using the authenticated user’s context. CSRF-token validation helps protect actions against unwanted cross-origin requests but does not replace authorization.

Apply and decide

Session cookies need attributes appropriate to transport and context. Following authentication changes, manage sessions according to framework/PHP guidance to reduce fixation. Use appropriate password-hashing APIs. HTML escaping, SQL parameterization, and authorization validation address different risks; implementing one does not remove the others.

Guided workplace application

A session identifies the account, but every read or change must still apply resource policy. Include lists, exports, and counts so other accounts’ data is not sent and merely hidden in the browser. A valid CSRF token does not grant ownership. Cookies also have distinct functions: HttpOnly limits access through script APIs, Secure restricts transmission to secure transport, and SameSite helps control sending contexts. Do not treat one attribute as a replacement for other controls. After authentication or privilege change, follow the framework/PHP session-renewal protocol and consider concurrent requests and expiry. Poorly coordinated renewal can disrupt legitimate users. The exercises apply public principles, not an internal policy of any bank.

IN PRACTICE

/invoice?id=52 must check whether the user may access invoice 52. Hiding the interface link does not protect the endpoint.

Common pitfalls

Authorizing only in the browser; overlooking aggregates; treating CSRF or HttpOnly as authorization.

Related topics: Explicit types and comparisons · Intentional arrays and functions

Take this idea with you

Authorized access must be enforced server-side for every operation.

Create account

Reference: OWASP: Authorization · PHP 8.5 reference; DR PHP 2026.2; new fixtures executed on PHP 8.3.17