session_destroy() but re-use session ID: security risk?
| From: | Johnson, Kirk | Date: | Thu, 01 May 2003 16:32:07 +0000 |
| Subject: | session_destroy() but re-use session ID: security risk? | ||
| Groups: | php.general | ||
| Request: | Send a blank email to php-general+get-145980@lists.php.net to get a copy of this message | ||
Say an application, using sessions, has a "logout" button which destroys the
session data. Say, also, that a user clicks that button, but then logs back
into the site without first closing their browser. Under these
circumstances, the session cookie and ID from their previous session will
get re-used for their new session. Is there any harm in this, from a
security viewpoint, or otherwise?
TIA
Kirk