Re: session security issue

From: Date: Wed, 15 Aug 2001 09:43:53 +0000
Subject: Re: session security issue
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-62811@lists.php.net to get a copy of this message
You need to check against a value that was registered as a session variable. There is no use in checking if some SSL variable is set. Here's a simplified version of my check_session function that I run at the top of every page that requires a session to be established. I also write to the session file on every click. This lets me know howmany sessions are "actually" active. I have a session deletion script that runs every minute to check the date of the session file, if it's older than a defined time it will remove the session file. The session deletion script is available at http://database.sf.net/ Any other ideas to make a session more secure? function check_session() { session_start(); if (session_is_registered(user_id)) { return TRUE; } else { header("Location: login.php"); exit; } }

« previous php.general (#62811) next »