Session

From: Date: Wed, 01 Nov 2000 21:32:54 +0000
Subject: Session
Groups: php.general 
Request: Send a blank email to php-general+get-23249@lists.php.net to get a copy of this message
Hello everyone! I have a pretty simple question. In my php.ini file I have session.gc_maxlifetime = 10 and I am not using cookies just the files that PHP4.0.3pl1 creates by default and I'm passing the session id in the URL. Now it is my understanding that after 10 seconds of inactivity the "stored data will be seen as 'garbage' and claned up by the gc process." This is not the case that I have found (maybe I'm reading this all wrong). What I do is I logon to my site which creates a new session. Then I let it sit there for over 10 seconds to test it out. After ten seconds I click on a link which passes the session id through the url. Now one would think that since I waited 10 seconds that all the session data that I had stored would be gone. Well it's not gone and the session for some reason is still active. My question is do I have to keep track of how long a user has been inactive etc throughout my pages and check to see if the session has timed out therefore destroying the session with session_destroy() (which isn't working because i get this warging: Warning: Session object destruction failed in c:\logoff.php3 on line 7. I'm finding that a lot of people are having problems with session_destroy() not working). And then Redirecting their browser to the logon page? Is there a function call you can use in php that will tell you true if the session id is a valid session that is currently in use and false if the session has timed out OR am I going to have to write that functionality into my program? Thanks, Jay Paulson

« previous php.general (#23249) next »