Re: extract($_POST)

From: Date: Wed, 23 Oct 2002 18:31:02 +0000
Subject: Re: extract($_POST)
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-121151@lists.php.net to get a copy of this message
> > That's not possible. I don't know how to explain it technically, but > > when you submit the form, your data is passed to an instance of the > > processing script and the script runs. Even if a dozen instances are all > > running at once, each only operates on the data that was passed to it by > > the user pressing submit. > > > > What are you "storing"?? > > I will be using sessions to keep things such as a user id while the end > user is traversing from page to page but I wasn't sure that it would make > sense to also store variable values as well in the session while they are > needed then drop them from the session when they are not. As long as each > process is secure enough to keep one person from getting another person's > values then it should be secure enough to use the extract($_POST) method > as opposed to using the $_POST['var'] method. It just seems that it would > be more effective to get all the values at once instead of writting out > every instance of $_POST['var'] for each individual 'var'. If this is the same thread that was worried about 1000s of visitors at the same time, then you may want to look into your own method of generating a unique session id. I've never seen it myself, but someone mentioned on here that under a heavy load, the "unique" session id that's created for a user could be one that's actually already in use, so now two people have the same session. Adjusting your garbage collection routines will help with that some, but using your own function for creating a larger, more unique, session id may be necessary. ---John Holmes...

« previous php.general (#121151) next »