Re: session security issue
| From: | speedboy | Date: | Wed, 15 Aug 2001 09:43:53 +0000 |
| Subject: | Re: session security issue | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-62811@lists.php.net to get a copy of this message | ||
You need to check against a value that was registered as a session
variable. There is no use in checking if some SSL variable is set. Here's
a simplified version of my check_session function that I run at the top of
every page that requires a session to be established.
I also write to the session file on every click. This lets me know howmany
sessions are "actually" active. I have a session deletion script that runs
every minute to check the date of the session file, if it's older than a
defined time it will remove the session file.
The session deletion script is available at http://database.sf.net/
Any other ideas to make a session more secure?
function check_session() {
session_start();
if (session_is_registered(user_id)) {
return TRUE;
} else {
header("Location: login.php");
exit;
}
}