This looks like it should work. Do you have a url where I can see the problem? Are you sure you uploaded the files after adding the session variable parameter? Are you switching to another id owned by that user or one they shouldn't be able to access?