Re: Override session id creation and cookie creation?
| From: | derick@php.net | Date: | Mon, 18 Feb 2002 14:37:03 +0000 |
| Subject: | Re: Override session id creation and cookie creation? | ||
| References: | 1 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-80147@lists.php.net to get a copy of this message | ||
On Mon, 18 Feb 2002 mlwmohawk@mohawksoft.com wrote:
> In my module, msession, I have routines that guarentee that a session id
> is unique within a cluster of web servers.
>
> The problem I have is that session creates and sets the session cookie
> without some mechanism to allow me to replace the session id string, prior
> to the session code setting the cookie.
>
> In some test code I have, I set the PHPSESSID cookie with my value, and
> replace the internal value used, but oddly enough both values exist in the
> browser, and depending on any set of random events, it is not predictable
> which PHPSESSID value gets used.
>
> Any hints? Tips?
We have the same problem with SRM, Sterling tried to fix it, but didn't
succeed in this yet. Sascha also added that it doesn't really matter who
creates the id, because MD5 is random enough anyways.
Derick