Re: where does php store session data?

From: Date: Sun, 27 Aug 2000 03:35:38 +0000
Subject: Re: where does php store session data?
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-13825@lists.php.net to get a copy of this message
> I'm not going to go into too much detail, but I'll give you some quick > answers. > > > Can anyone explain to me (or direct me to another resource that explains) > > the innerworkings of PHP4 sessions? I need to know what's going on behind > > the scenes. > > They are immensely customizable, the session data can be stored in files > (default), databases, anywhere someone has written a session module > for. The session id's can be created using millisecond time or a source of > random entropy. By default the session data is stored in files in the > system temporary directory (normally /tmp) and the ids are generated using > tyhe millisecond time on the server. The client only needs to know the > session id, which it usually submits via a cookie. This clears up a lot of stuff for me. User authentication is not quite as complicated now (although the initial login page still is). > > The session files are 'garbage collected'. That is, a timelimit can be set > in php.ini, if the garbage collector is run, files older than that are > deleted. The garbage collector is invoked by php during any transaction > based on a random probability, which you can configure in php.ini too. > > > Does PHP check to make sure that the client-side data has not been altered > > by comparing it to the server-side data? > > The client stores only the session id, so there is nothing to be altered > on the client side. Well, this makes it a bit easier, but I'll still need to check for my own users trying to get access to other people's accounts through my web login. (Yes, I am that paranoid.) Security threats don't just come from the outside world, after all. Thanks a lot for your explanation. Dean Hall.

« previous php.general (#13825) next »