RE: [PHP] Sessions
| From: | Jon Haworth | Date: | Thu, 24 Oct 2002 12:21:41 +0000 |
| Subject: | RE: [PHP] Sessions | ||
| Groups: | php.general | ||
| Request: | Send a blank email to php-general+get-121243@lists.php.net to get a copy of this message | ||
Hi Ed,
> If I use session_start() after someone authenticates
> I should then be able to do session_register('$id')
> and that persons username is kept as a record in that
> person's session.
Spot on.
> As far as I have tested the above, I can then go to a
> seperate page and do session_start() again and be able
> to pull the $id variable from that session.
Spot on again.
> As far as I can tell this is all done server side without
> cookies or doing anything with the session id in the URL.
Bzzt ;-)
PHP will allocate a "session ID" to each visitor. This is (usually) a
32-character string and (usually) called "PHPSESSID".
This string is offered to the visitor in a cookie, but if they refuse it,
PHP will just append it to the end of every URL automatically.
> How does PHP know that a specific session is this or that
> person's session?
Every time you call session_start(), PHP reads the session ID either from
the cookie or the URL.
It then loads the session file stored on the server (usually in /tmp), reads
the variables that you've registered, and makes them available in the
$_SESSION superglobal array.
Every so often, any old session files are deleted (which is why your
sessions expire after a while).
HTH
Cheers
Jon