Re: Session IP address matching

From: Date: Sat, 25 Jan 2014 07:42:05 +0000
Subject: Re: Session IP address matching
References: 1 2 3 4 5 6 7  Groups: php.internals 
Request: Send a blank email to internals+get-71549@lists.php.net to get a copy of this message
Hi all, On Sat, Jan 25, 2014 at 4:32 PM, Yasuo Ohgaki <yohgaki@ohgaki.net> wrote: > On Sat, Jan 25, 2014 at 12:09 PM, Andrey Andreev <narf@devilix.net> wrote: > >> Still, that is not optimal. The desired effect is to call the session file >> something like: >> >> <session.name>_<REMOTE_ADDR(hash)>_<session_id> >> >> I can't think of a way of making that happen, so I guess a work-around >> would be to do: >> > > I've just written session_create_id(string $prefix) today. > You can do that easily and securely with session_create_id(). > It would be in 5.6. > > You may check easily with user script whatever prefix means. > > NOTE: No one should not expose sensitive data in prefix! > If anyone would like to prefix by IP address, store it like session_create_id(sha1($secret.$IP_ADDR).'-'); Regards, -- Yasuo Ohgaki yohgaki@ohgaki.net

« previous php.internals (#71549) next »