Re: Session IP address matching

From: Date: Sat, 25 Jan 2014 07:32:10 +0000
Subject: Re: Session IP address matching
References: 1 2 3 4 5 6  Groups: php.internals 
Request: Send a blank email to internals+get-71548@lists.php.net to get a copy of this message
Hi Andrey, On Sat, Jan 25, 2014 at 12:09 PM, Andrey Andreev <narf@devilix.net> wrote: > Still, that is not optimal. The desired effect is to call the session file > something like: > > <session.name>_<REMOTE_ADDR(hash)>_<session_id> > > I can't think of a way of making that happen, so I guess a work-around > would be to do: > I've just written session_create_id(string $prefix) today. You can do that easily and securely with session_create_id(). It would be in 5.6. You may check easily with user script whatever prefix means. NOTE: No one should not expose sensitive data in prefix! Regards, -- Yasuo Ohgaki yohgaki@ohgaki.net

« previous php.internals (#71548) next »