Re: Session IP address matching
| From: | Yasuo Ohgaki | Date: | Sun, 26 Jan 2014 01:08:26 +0000 |
| Subject: | Re: Session IP address matching | ||
| References: | 1 2 3 4 5 6 7 8 9 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-71577@lists.php.net to get a copy of this message | ||
Hi Stas,
On Sun, Jan 26, 2014 at 10:00 AM, Yasuo Ohgaki <yohgaki@ohgaki.net> wrote:
> On Sun, Jan 26, 2014 at 9:44 AM, Stas Malyshev <smalyshev@sugarcrm.com>wrote:
>
>> > which is really bad thing to do. session_create_id() generate ID using
>> > the same code PHP generates ID which is much secure than above and
>> > supposed to be faster than user land script.
>>
>> I agree that exposing the ID creation function is a good addition
>> (actually if it was available I'd probably use it in other contexts
>> where I need a random token, not necessarily a session ID as such).
>> Maybe we need even more generic function and have session reuse that
>> code, too.
>
>
> Although I've written it already, I appreciate any comments for
> improvement. Do you have idea for session_create_id()?
> Perhaps, more generic function name and/or move to ext/standard?
>
An idea for session_id().
It would be better to allow session_id() to set SID regardless of
use_strict_mode. It's programmer's intention.
Should I make this change from 5.5? It's nicer than now.
Regards,
--
Yasuo Ohgaki
yohgaki@ohgaki.net