Re: [RFC] Secure Session Module Options by Default
| From: | Yasuo Ohgaki | Date: | Sat, 01 Feb 2014 23:59:59 +0000 |
| Subject: | Re: [RFC] Secure Session Module Options by Default | ||
| References: | 1 2 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-71954@lists.php.net to get a copy of this message | ||
Hi Stas,
On Sun, Feb 2, 2014 at 7:52 AM, Stas Malyshev <smalyshev@sugarcrm.com>wrote:
> > Secure Session Module Options by Default
> > https://wiki.php.net/rfc/secure-session-options-by-default
>
> use_strict_mode - I'm not sure I understand what "Change session_id() to
> allow any id regardless of this mode." means. Since there's no patch
> attached, could you explain the change in more detail?
When use_strice_mode=On,
session_id($some_new_id);
will generate random session ID, since there is no initialized session data
for it. (This is what use_strict_mode=On supposed to do)
However, user may set their own session ID which contains some data in
session ID name via session_create_id([string $prefix]). e.g. time
created/regenerated/etc.
To set user defined session ID, user has to do
ini_set('session.use_strict_mode', FALSE);
session_id(session_create_id('SOME-USEFUL-PREFIX'));
With this change, user could do
session_id(session_create_id('SOME-USEFUL-PREFIX'));
regardless of INI settings. session_id() is changed to modify
'session.use_strict_mode' INI to off internally. This change is not
mandatory as user may change INI by themselves. It's for convenience. I
don't mind at all withdrawing this change from the RFC.
Regards,
--
Yasuo Ohgaki
yohgaki@ohgaki.net