From: Eric Schwartz Date: 2004-05-12T04:03:52+09:00 Subject: Re: [OT] Web, Cookies and Sessions "Kirk Haines" writes: > I don't think there's any magic other than trying to deliver a cookie when > they first arrive at your site and then seeing if it's there on the next > transaction. You can get a bit sneaky, if you're willing to trust your users a little. OTOH, if you're using cookies, you're *already* trusting the user to not be malicious, at least a bit. The algorithm looks like: On any page load: 1) Check if there's a cookie. If so, all is well, exit. 2) Check if HTTP_REFERER (note spelling) comes from the same site. If not, then set a cookie. 3) At this point, you know you don't have a cookie, and the user claims to have already been on your site, which means they won't accept cookies, so set your rewrite_url flag. Note that this algorithm is riddled with places for assumptions to be proven false, the most obvious of which is that HTTP_REFERER is trivially spoofable. It also doesn't account for situations where you only want to set a cookie if the visitor visits a certain subset of URIs. But then, cookies themselves are trivially editable from the client side as well, so that's not really so bad. Also, note that this isn't really different from what you said, Kirk; I just thought of it as I was reading your post. Think of it more as an expansion on a theme. But in any event, this really has nothing to do with Ruby at all, so I'm setting followups to CIWAC, where they know about this sort of thing, and are probably going to be able to give the OP a better answer than most people here can. -=Eric -- Come to think of it, there are already a million monkeys on a million typewriters, and Usenet is NOTHING like Shakespeare. -- Blair Houghton.