Re: session id generation
| From: | Ernest E Vogelsinger | Date: | Wed, 12 Mar 2003 19:22:18 +0000 |
| Subject: | Re: session id generation | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-139372@lists.php.net to get a copy of this message | ||
At 19:50 12.03.2003, Mathieu Dumoulin spoke out and said:
--------------------[snip]--------------------
>Hi, i'd like to know how PHP determines what session_id to hand out to
>users.
>
>Is it based on some real value like the browser and the ip address? an
>incremental number? I want to make sure that it doesnt provide two same
>session id for the different users at the same time.
--------------------[snip]--------------------
{php_source_directory}/ext/session/session.c
this has it all - look for _php_create_id().
Basically it generates an MD5 digest from the current secs and usecs
(system time) and a pseudo-random number (see php_combined_lcg() in
standard/lcg.c). If an entropy file is available (usually on unix systems)
it uses the entropy to further randomize the digest. In a final step the
digest is converted to a hex string.
--
>O Ernest E. Vogelsinger
(\) ICQ #13394035
^ http://www.vogelsinger.at/