Re: Session IP address matching

From: Date: Sun, 26 Jan 2014 01:08:26 +0000
Subject: Re: Session IP address matching
References: 1 2 3 4 5 6 7 8 9  Groups: php.internals 
Request: Send a blank email to internals+get-71577@lists.php.net to get a copy of this message
Hi Stas, On Sun, Jan 26, 2014 at 10:00 AM, Yasuo Ohgaki <yohgaki@ohgaki.net> wrote: > On Sun, Jan 26, 2014 at 9:44 AM, Stas Malyshev <smalyshev@sugarcrm.com>wrote: > >> > which is really bad thing to do. session_create_id() generate ID using >> > the same code PHP generates ID which is much secure than above and >> > supposed to be faster than user land script. >> >> I agree that exposing the ID creation function is a good addition >> (actually if it was available I'd probably use it in other contexts >> where I need a random token, not necessarily a session ID as such). >> Maybe we need even more generic function and have session reuse that >> code, too. > > > Although I've written it already, I appreciate any comments for > improvement. Do you have idea for session_create_id()? > Perhaps, more generic function name and/or move to ext/standard? > An idea for session_id(). It would be better to allow session_id() to set SID regardless of use_strict_mode. It's programmer's intention. Should I make this change from 5.5? It's nicer than now. Regards, -- Yasuo Ohgaki yohgaki@ohgaki.net

« previous php.internals (#71577) next »