9
Quote:
so that the auto-login option stays on all the time. Hopefully that was a good idea....
The risk here is to people that access the site from a public place or a physically unsecured compter. A computer lab in a university for example.
When person A logs in, since his session can't time out in the usual way, when another person, B, comes up later in the day and goes to your site person B will be logged in as person A. It's a pretty blatent security hole that I'm sure you didn't intend.
Terrion
Purchase, renew, or transfer your domain name to
Ultranet Domains and get a FREE 10GB hosting account. Virtual Dedicated Servers around $35/monthly, no contract. FREE 24/7 telephone ...