Re: Session Security Issue
I did something on this line for my old job. I had to limit the amount of information a person saw and could use. I didnt need serious protection so I just got creative.
The passwords each had 3 values hidden in it, such as "12A34B56C". It just looked random but those 3 letters meant something. When they first logged in I stripped thos characters and then those meant thier levels. AAA ment they could do anything, ABA ment they could not delete information but could do everything else.
Then in the code, I had those 3 characters passed through the pages, something like mainpage.php?action=new&val1=profile&psl=ABC, etc
PSL = Persons security level. then every page checked these. I am sure its not what you need but incase anyone else wonders, this is how I did it.