Session management.

From: Date: Mon, 22 May 2000 03:58:12 +0000
Subject: Session management.
Groups: php.general 
Request: Send a blank email to php-general+get-266@lists.php.net to get a copy of this message
Hi, I am exploring the session management features of PHP4. I have a web application where the user logs in and can use several features. I am able to start the session and store variables and use them in other pages. I want to know how to check if a session is already active. I need this check in order to prevent unauthorised access. Another thing is that when I call the session_destroy() to end my session, php will destroy the session from the server, ie remove the session file but it will not destroy the cookie. I tried to destroy the cookie manually by calling setcookie("PHPSESSID", 0) but this just doesnt work. I tried to give it the correct domain names and path but still it does not work. The old value of cookie is still kept. I want destroy the cookie so that when the user logs in again before the cookie times out, they will get a new session id. I have found several documents on how to use the session management feature in php4 but I havnt been able to find any documents that talk about how to do it securly. The methods described in the manual and on phpbuilder.com do not prevent unauthorised access. All a hacker needs is an active sessionid and they can get into the system. I am using PHP4 RC2 on apache Red Hat 6.0. I would appreciate all the help I can get. Best regards, Vikash. Visit us at http://www.foodeasy.com

« previous php.general (#266) next »