Re: Sessions: APACHE HACK instead of -trans-sid?
| From: | Brian Clark | Date: | Mon, 20 Nov 2000 20:26:31 +0000 |
| Subject: | Re: Sessions: APACHE HACK instead of -trans-sid? | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-26330@lists.php.net to get a copy of this message | ||
Hello Derek,
(DS == "Derek Sivers") list@hitmedia.com writes:
DS> I've heard the other alternative to PHP's --enable-trans-sid option is an
DS> Apache hack.
DS>
DS> I've seen it used on Amazon.com. It appends a unique ID at the end of your
DS> URL *ALWAYS*, at the Apache level, not the HTML/PHP level, and just knows
DS> to filter it out and process the other parts of the URL that it needs.
Web Application Development with PHP 4.0 (Good book. ISBN:
0-7357-0997-1) talks about this very thing.
From the book:
The rewrite rule for use with mod_rewrite:
RewriteEngine On
RewriteBase /
RewriteRule ^[0-9a-z]{32}/(.+) /$1
The function:
function session_start_from_rewrite()
{
global $HTTP_HOST,$REQUEST_URI;
ereg(/([0-9a-z ]{32}),$REQUEST_URI,$regs);
$session_id =$regs [1 ];
if(!isset($session_id)||empty($session_id))
{
srand((double)microtime()*1000000);
$session_id =md5(uniqid(rand()));
$destination =http://$HTTP_HOST/$session_id$REQUEST_URI ;
header(Location:$destination );
}
session_id($session_id);
session_start();
}
DS> My site is already doing something similar to this. And I own/run the
DS> server, and can hack-up Apache all I want.
DS>
DS> Does anyone know HOW to do it though, or perhaps direct me to a URL about
DS> what mod_rewrite-type thing I need?
DS>
DS> (I'm asking my PHP friends here, because you guys already know what
DS> --enable-trans-sid is...)
-Brian
--
Life is a sexually transmitted disease with a 100%
mortality rate. -- David Shaw