Re: PHP 4.0 Bug #6983: session_destroy() does not remove session
| From: | Sascha Schumann | Date: | Tue, 03 Oct 2000 18:29:26 +0000 |
| Subject: | Re: PHP 4.0 Bug #6983: session_destroy() does not remove session | ||
| References: | 1 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-34187@lists.php.net to get a copy of this message | ||
On Tue, 3 Oct 2000, Teodor Cimpoesu wrote:
> Hi André!
> On Tue, 03 Oct 2000, André Langhorst wrote:
>
> > > from what I remember,session-destroy doesn't delete the session cookie
> > > (least I haven't see the code to do that in session.c).
> > > try
> > >
> > > session_destroy();
> > > Header("Location: <homepageurl>");
> > > SetCookie (session_name(),'',0,'/');
> >
> > IIRC this ought to, session_destroy() destroys session data not session
> > itself
> >
> hmm, just that
destroy' and free' are doing kindof
> the same thing.
> I would have expected `destroy' to destroy the session,which includes IMO
> invalidating the session id.
When the session data is gone, the session id automatically
becomes invalid. There is no necessity to manually delete the
cookie from the client.
- Sascha