session restarted after session_destroy()

From: Date: Tue, 18 Apr 2000 15:35:26 +0000
Subject: session restarted after session_destroy()
References: 1  Groups: php.dev 
Request: Send a blank email to php-dev+get-18019@lists.php.net to get a copy of this message
php4rc1 The following script creates a session containing "ses_sToto="session OK". Load it with your browser. Verify that the session is created by reloading the page. Write down the session_id. Destroy the session (append "?destroy=1" to the URL) and verify that the session no longer exists in /tmp. Refresh the page in your browser: a new session is created, but it has the same SID ! As the cookie still exists in the browser, the browser sends it to the script, and PHP, create the session, with the given SID. Php should generate a new SID if the SID given by the browser does not exist. The problem is that with a login/passwd registering function, a session can be restarted by pushing the 'back' button in the browser. This is very annoying for a login/password session type, the l/p infos are passed as POST. The session is then destroyed. But if you click 'back', you are automatically relogged ! I did a trick to overcome this 'bug/feature' by passing also the SID with the POST variables <?php session_start(); session_register("ses_sToto"); if ($destroy==1) { session_detroy(); print "session destroyed"; } else { print("session_id()=".session_id()); if ($ses_sToto=="") $ses_sToto="session OK"; } ?> ./configure --with-mysql --with-apache=../apache_1.3.12 --enable-track-vars

« previous php.dev (#18019) next »