Re: Session IP address matching
| From: | Yasuo Ohgaki | Date: | Sat, 25 Jan 2014 07:42:05 +0000 |
| Subject: | Re: Session IP address matching | ||
| References: | 1 2 3 4 5 6 7 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-71549@lists.php.net to get a copy of this message | ||
Hi all,
On Sat, Jan 25, 2014 at 4:32 PM, Yasuo Ohgaki <yohgaki@ohgaki.net> wrote:
> On Sat, Jan 25, 2014 at 12:09 PM, Andrey Andreev <narf@devilix.net> wrote:
>
>> Still, that is not optimal. The desired effect is to call the session file
>> something like:
>>
>> <session.name>_<REMOTE_ADDR(hash)>_<session_id>
>>
>> I can't think of a way of making that happen, so I guess a work-around
>> would be to do:
>>
>
> I've just written session_create_id(string $prefix) today.
> You can do that easily and securely with session_create_id().
> It would be in 5.6.
>
> You may check easily with user script whatever prefix means.
>
> NOTE: No one should not expose sensitive data in prefix!
>
If anyone would like to prefix by IP address, store it like
session_create_id(sha1($secret.$IP_ADDR).'-');
Regards,
--
Yasuo Ohgaki
yohgaki@ohgaki.net