Re: PHPSESSID Question
| From: | Richard Lynch | Date: | Mon, 08 Jan 2001 06:08:35 +0000 |
| Subject: | Re: PHPSESSID Question | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-33191@lists.php.net to get a copy of this message | ||
Session IDs are just cookies sent to the browser and returned by the
browser.
I think if you turned off the usage of cookies entirely, and went on just
the URL-based Session IDs you would not see that behaviour...
You could write your own destroy_session() function which called
SetCookie(PHPSESSID, ''). But it would have to be at the very tip-top of a
page for the Cookie to be effective. And the session/cookie would remain
active on the remainder of that same page -- since only on the *next* page
is the value "forgotten".
----- Original Message -----
From: "Shane McBride" <php@riversidedesigns.net>
Newsgroups: php.general
Sent: Saturday, January 06, 2001 6:35 PM
Subject: [PHP] PHPSESSID Question
I have been trying to learn about sessions lately.
I have been successful in start and destroying a session, but when I start a
session right after destroying a session, I get the same PHPSESSID. I can
actually watch the tmp file get deleted and then recreated only to get the
same PHPSESSID.
I tried from two different machines and went like this:
Machine 1 = started session
Machine 2 = started session
Machine 1 = destroyed session
Machine 2 = destroyed session
Then I did the same process starting with Machine 2. I got the same
PHPSESSID as I did for Machine 2 the first time.
The only way to get a new PHPSESSID was to close the browser out.
This quite frankly sucks. I would think a new PHPSESSID would be assigned
after each and every destroy.
Any thoughts?
TIA,
Shane