On Mon, Jul 7, 2008 at 2:47 PM, mike <mike503@xxxxxxxxx> wrote: > > I don't see why if you -know- you need $_COOKIE['username'] someone > would be lazy and use $_REQUEST['username'] That's the point --- it's intended as a fallback where you *don't* know the method that will be used, or if you want to be lackadaisical with your code (which, as we all know, is HIGHLY unrecommended). So if you are an application service provider (ASP) who, perhaps, runs a simple word shuffling script, with no database, email, or other externally-processed services, you may have a script like so: <?php $word = $_REQUEST['word']; echo str_shuffle($word)."<br />\n"; ?> Because, in this case, it really doesn't matter if $word is obtained via GET or POST, so you can allow external users to use your service via an HTTP POST form or a plain URL. Conversely, it can also be used as a login mechanism or other secure system, if you know what you're doing with regard to EGPCS (which I mentioned to the wrong poster before! :-\) and proper secure coding techniques. It will go through a matter of precedence, which can be useful in some (rare) circumstances. -- </Daniel P. Brown> Dedicated Servers - Intel 2.4GHz w/2TB bandwidth/mo. starting at just $59.99/mo. with no contract! Dedicated servers, VPS, and hosting from $2.50/mo. -- PHP General Mailing List (http://www.php.net/) To unsubscribe, visit: http://www.php.net/unsub.php