Re: Re: Session cache, lock and write
| From: | Adam Harvey | Date: | Thu, 14 Nov 2013 20:00:56 +0000 |
| Subject: | Re: Re: Session cache, lock and write | ||
| References: | 1 2 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-70124@lists.php.net to get a copy of this message | ||
On 14 November 2013 11:54, Yasuo Ohgaki <yohgaki@ohgaki.net> wrote:
> I also would like to add "session deletion delay" to mitigate session
> deletion
> race condition by adding deletion time in session data. (i.e
> session_regenerate_id(true)
> may create multiple valid sessions. This can be mitigated by having this)
>
> session.deletion_delay = int (by default 0 = delete immediately. 10 for 10
> sec later)
>
> If there is $_SESSION['__SESSION_EXPIRE__'] and expired, new session ID is
> created
> automatically.
>
> I would like to hear comments for this also.
As a nitpick, I think I'd rather this was controlled by a function
than a magic $_SESSION key, at least in userland — conceptually, it's
simpler to explain to users if everything in $_SESSION is always
persisted and it never affects behaviour.
+1 on the idea, though.
Adam