Session management.
| From: | Vikash Khatuwala | Date: | Mon, 22 May 2000 03:58:12 +0000 |
| Subject: | Session management. | ||
| Groups: | php.general | ||
| Request: | Send a blank email to php-general+get-266@lists.php.net to get a copy of this message | ||
Hi,
I am exploring the session management features of PHP4.
I have a web application where the user logs in and can use several features.
I am able to start the session and store variables and use them in other pages.
I want to know how to check if a session is already active. I need this check
in order to prevent unauthorised access.
Another thing is that when I call the session_destroy() to end my session, php
will destroy the session from the server, ie remove the session file but it
will not destroy the cookie. I tried to destroy the cookie manually by calling
setcookie("PHPSESSID", 0) but this just doesnt work. I tried to give it the
correct domain names and path but still it does not work. The old value of cookie
is still kept. I want destroy the cookie so that when the user logs in again
before the cookie times out, they will get a new session id.
I have found several documents on how to use the session management feature
in php4 but I havnt been able to find any documents that talk about how to do
it securly. The methods described in the manual and on phpbuilder.com do not
prevent unauthorised access. All a hacker needs is an active sessionid and
they can get into the system.
I am using PHP4 RC2 on apache Red Hat 6.0.
I would appreciate all the help I can get.
Best regards,
Vikash.
Visit us at http://www.foodeasy.com