Session
| From: | Paulson, Joseph V. \"Jay\" | Date: | Wed, 01 Nov 2000 21:32:54 +0000 |
| Subject: | Session | ||
| Groups: | php.general | ||
| Request: | Send a blank email to php-general+get-23249@lists.php.net to get a copy of this message | ||
Hello everyone!
I have a pretty simple question. In my php.ini file I have
session.gc_maxlifetime = 10 and I am not using cookies just the files that
PHP4.0.3pl1 creates by default and I'm passing the session id in the URL.
Now it is my understanding that after 10 seconds of inactivity the "stored
data will be seen as 'garbage' and claned up by the gc process." This is
not the case that I have found (maybe I'm reading this all wrong). What I
do is I logon to my site which creates a new session. Then I let it sit
there for over 10 seconds to test it out. After ten seconds I click on a
link which passes the session id through the url. Now one would think that
since I waited 10 seconds that all the session data that I had stored would
be gone. Well it's not gone and the session for some reason is still
active.
My question is do I have to keep track of how long a user has been inactive
etc throughout my pages and check to see if the session has timed out
therefore destroying the session with session_destroy() (which isn't working
because i get this warging: Warning: Session object destruction failed in
c:\logoff.php3 on line 7. I'm finding that a lot of people are having
problems with session_destroy() not working). And then Redirecting their
browser to the logon page?
Is there a function call you can use in php that will tell you true if the
session id is a valid session that is currently in use and false if the
session has timed out OR am I going to have to write that functionality into
my program?
Thanks,
Jay Paulson