session restarted after session_destroy()
| From: | Gilles Bouthenot | Date: | Tue, 18 Apr 2000 15:35:26 +0000 |
| Subject: | session restarted after session_destroy() | ||
| References: | 1 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-18019@lists.php.net to get a copy of this message | ||
php4rc1
The following script creates a session containing "ses_sToto="session OK".
Load it with your browser.
Verify that the session is created by reloading the page. Write down the session_id.
Destroy the session (append "?destroy=1" to the URL) and verify that the session no longer exists in /tmp.
Refresh the page in your browser: a new session is created, but it has the same SID !
As the cookie still exists in the browser, the browser sends it to the script, and PHP,
create the session, with the given SID.
Php should generate a new SID if the SID given by the browser does not exist.
The problem is that with a login/passwd registering function, a session can be restarted
by pushing the 'back' button in the browser.
This is very annoying for a login/password session type, the l/p infos are passed as POST.
The session is then destroyed.
But if you click 'back', you are automatically relogged !
I did a trick to overcome this 'bug/feature' by passing also the SID with the POST variables
<?php
session_start();
session_register("ses_sToto");
if ($destroy==1)
{
session_detroy();
print "session destroyed";
}
else
{
print("session_id()=".session_id());
if ($ses_sToto=="")
$ses_sToto="session OK";
}
?>
./configure --with-mysql --with-apache=../apache_1.3.12 --enable-track-vars