Forum Moderators: coopster
Cookies can be disabled so that's probably not the best approach. What about sessions? What are the pros and cons of using sessions for this? How about a time-based limiter? For either of these methods, can the user be identified somehow other than IP number? I would like to avoid compromising usability for browsers behind a proxy server.
All input appreciated.
They could still go back to the first step and start again as they would receive a new token/string.