Re: Regenerating session ID automatically when IP address has changed

From: Date: Wed, 25 Sep 2013 03:52:16 +0000
Subject: Re: Regenerating session ID automatically when IP address has changed
References: 1 2  Groups: php.internals 
Request: Send a blank email to internals+get-69328@lists.php.net to get a copy of this message
Hi, On Tue, Sep 24, 2013 at 12:46 PM, Ronald Chmara <ronabop@gmail.com> wrote: > When you have a group of front-end termination points in a pool, proxying > requests off to hundreds of machines for thousands of applications, tying a > session to any IP is a headache. IMO, sessions are supposed to be tied to > users, not any given inbound IP that can, and may, jump between different > routers, proxies, NAT hosts, etc. Session is tied to specific user(browser) regardless of IP unless session ID is hijacked. Renewing session ID does not matter. Regenerating session ID when IP has changed would help users to notice session hijack. This is the sole purpose of regenerating session ID when IP has changed. I think only few apps do this now. Regards, -- Yasuo Ohgaki yohgaki@ohgaki.net

« previous php.internals (#69328) next »