Re: Session security

From: Date: Tue, 29 May 2007 20:49:06 +0000
Subject: Re: Session security
References: 1 2 3 4 5 6 7 8 9 10 11 12 13 14  Groups: php.internals 
Request: Send a blank email to internals+get-29898@lists.php.net to get a copy of this message
Stut wrote:
It doesn't matter where the session ID comes from, the basic point is that you have to trust it or implement some experience-degrading mechanism like client certificates, and even there there are few guarantees.
You want more info to be checked? Simply add a variable containing user-agent, remove ip, etc. to your session and check that in your application startup code. If it doesn't match then start a new session. But as this can lead to various problems (user agent being easy to fake and not necessarily constant through proxies, remote ip changing in the middle of a session with proxies or some providers) this should be done when really needed by the application, not by PHP itself. I'm pretty sure there already exists a PEAR package or something helping with this. My 2 cents, - Chris

« previous php.internals (#29898) next »