Re: where does php store session data?
| From: | Dean Hall | Date: | Sun, 27 Aug 2000 03:35:38 +0000 |
| Subject: | Re: where does php store session data? | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-13825@lists.php.net to get a copy of this message | ||
> I'm not going to go into too much detail, but I'll give you some quick
> answers.
>
> > Can anyone explain to me (or direct me to another resource that
explains)
> > the innerworkings of PHP4 sessions? I need to know what's going on
behind
> > the scenes.
>
> They are immensely customizable, the session data can be stored in files
> (default), databases, anywhere someone has written a session module
> for. The session id's can be created using millisecond time or a source of
> random entropy. By default the session data is stored in files in the
> system temporary directory (normally /tmp) and the ids are generated using
> tyhe millisecond time on the server. The client only needs to know the
> session id, which it usually submits via a cookie.
This clears up a lot of stuff for me. User authentication is not quite as
complicated now (although the initial login page still is).
>
> The session files are 'garbage collected'. That is, a timelimit can be set
> in php.ini, if the garbage collector is run, files older than that are
> deleted. The garbage collector is invoked by php during any transaction
> based on a random probability, which you can configure in php.ini too.
>
> > Does PHP check to make sure that the client-side data has not been
altered
> > by comparing it to the server-side data?
>
> The client stores only the session id, so there is nothing to be altered
> on the client side.
Well, this makes it a bit easier, but I'll still need to check for my own
users trying to get access to other people's accounts through my web login.
(Yes, I am that paranoid.) Security threats don't just come from the outside
world, after all.
Thanks a lot for your explanation.
Dean Hall.