gc_maxlifetime shouldn't always be INI_ALL
| From: | Giancarlo | Date: | Sun, 18 Aug 2002 10:31:38 +0000 |
| Subject: | gc_maxlifetime shouldn't always be INI_ALL | ||
| Groups: | php.dev | ||
| Request: | Send a blank email to php-dev+get-86998@lists.php.net to get a copy of this message | ||
In a vhost environment, it seems tat any script can flush all existing
sessions that use the common save_path by lowering his gc_maxlifetime and
seting his gc_probability to 100%.
Both gc_maxlifetime and gc_probability values are INI_ALL, even when the
sessio.save_path is set to everybody's cauldron, on /tmp.
This will make possible for any vhost to block other vhosts' session
management.
Maybe it should be INI_ALL *only* when a particular save_path is specified,
so that will influence only his sessions?
Or does it exist some fault setting by which anyone could have the privileges
to force gc on some other vhosts' session by specifying *also* the other
vhost's save_path?
Giancarlo