Re: session id generation

From: Date: Wed, 12 Mar 2003 19:22:18 +0000
Subject: Re: session id generation
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-139372@lists.php.net to get a copy of this message
At 19:50 12.03.2003, Mathieu Dumoulin spoke out and said: --------------------[snip]-------------------- >Hi, i'd like to know how PHP determines what session_id to hand out to >users. > >Is it based on some real value like the browser and the ip address? an >incremental number? I want to make sure that it doesnt provide two same >session id for the different users at the same time. --------------------[snip]-------------------- {php_source_directory}/ext/session/session.c this has it all - look for _php_create_id(). Basically it generates an MD5 digest from the current secs and usecs (system time) and a pseudo-random number (see php_combined_lcg() in standard/lcg.c). If an entropy file is available (usually on unix systems) it uses the entropy to further randomize the digest. In a final step the digest is converted to a hex string. -- >O Ernest E. Vogelsinger (\) ICQ #13394035 ^ http://www.vogelsinger.at/

« previous php.general (#139372) next »