Sun, 4 Feb 2007 23:14:44 +0100 from HansH <hansh@invalid.invalid>:
> Bare in mind the HTTP_REFERER is
> - easy to temper wiht
> - will be blank if the form was bookmarked
> - might be disabled in some browser
> - might be removed or trimmed by some anti-virus or firewall software
Thanks for the reminders. The referrer is interesting information in
this particular application, but not critical. There's no particular
advantage to anyone suppressing or disabling it, but nothing awful
happens if they do.
I've already tested, and my form works right even if there's no
referrer, i.e. if someone goes directly to the page.
Again, thanks for the reminder -- and thanks for the initial pointer.
--
Stan Brown, Oak Road Systems, Tompkins County, New York, USA
http://OakRoadSystems.com/