RE: [PHP] Sessions

From: Date: Thu, 24 Oct 2002 12:21:41 +0000
Subject: RE: [PHP] Sessions
Groups: php.general 
Request: Send a blank email to php-general+get-121243@lists.php.net to get a copy of this message
Hi Ed, > If I use session_start() after someone authenticates > I should then be able to do session_register('$id') > and that persons username is kept as a record in that > person's session. Spot on. > As far as I have tested the above, I can then go to a > seperate page and do session_start() again and be able > to pull the $id variable from that session. Spot on again. > As far as I can tell this is all done server side without > cookies or doing anything with the session id in the URL. Bzzt ;-) PHP will allocate a "session ID" to each visitor. This is (usually) a 32-character string and (usually) called "PHPSESSID". This string is offered to the visitor in a cookie, but if they refuse it, PHP will just append it to the end of every URL automatically. > How does PHP know that a specific session is this or that > person's session? Every time you call session_start(), PHP reads the session ID either from the cookie or the URL. It then loads the session file stored on the server (usually in /tmp), reads the variables that you've registered, and makes them available in the $_SESSION superglobal array. Every so often, any old session files are deleted (which is why your sessions expire after a while). HTH Cheers Jon

« previous php.general (#121243) next »