Re: Strict session?
| From: | Yasuo Ohgaki | Date: | Fri, 02 Dec 2011 05:34:53 +0000 |
| Subject: | Re: Strict session? | ||
| References: | 1 2 3 4 5 6 7 8 9 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-56712@lists.php.net to get a copy of this message | ||
2011/12/2 Daniel K. <dk@uw.no>:
> Yasuo Ohgaki wrote:
>>
>> 2011/12/2 Yasuo Ohgaki <yohgaki@ohgaki.net>:
>>>
>>> I think Daniel mean there are extra spaces for indent.
>>> I'll fix it.
>
>
> That's exactly it, however the updated patch still has problems.
>
> Search for a + followed by only tabs or spaces. Empty lines should be
> just that, empty.
Does CODING_STANDARDS mention this?
>>> Since Daniel mentioned that he cannot disable strict session,
>
>
> I did no such thing. from where did you get that idea?
>
Because you wrote this.
> This could never work with:
>
> session_id("foo");
> session_start();
>
> could it?
I think you understands it can be controlled by session.use_strict_mode now.
> I am in serious doubt as to whether the additonal restrictions on valid
> characters in session ids are appropriate, and I fear that some poor sod may
> be in for a nasty surpris because of this.
>
> Remember, this is not just about the return value of hash functions, as this
> is used to validate session_ids set with session_id() as well.
With strict session, user cannot set session ID. If user can, it's not
a strict session, but adoptive.
If user would like to use adoptive session, user may set
session.use_strict_mode=0.
Regards,
--
Yasuo Ohgaki
yohgaki@ohgaki.net