Re: Removing base class from session handler

From: Date: Sun, 25 Jan 2015 02:54:59 +0000
Subject: Re: Removing base class from session handler
References: 1 2 3 4 5 6 7 8 9  Groups: php.internals 
Request: Send a blank email to internals+get-81104@lists.php.net to get a copy of this message
Hi again, On Sat, Jan 24, 2015 at 7:48 PM, Yasuo Ohgaki <yohgaki@ohgaki.net> wrote: > Hi Andrey, > > On Sat, Jan 24, 2015 at 6:34 PM, Andrey Andreev <narf@devilix.net> wrote: >> >> > This is because session module lacks user defined serializer. Save >> > handler >> > handles session data storage. Serialize handler handles how data is >> > converted/represented. IMHO. >> > >> >> That's not the only use case. >> >> Some time ago I proposed a session.match_ip feature and argued that if >> I wanted to implement it in userland code, I'd have to implement the >> *whole* session handler from scratch. An example using the >> SessionHandler class proved me wrong in that regard. > > > For me, IP address matching check does not belong to save handler. > I would implement it in other place. > > What's the reason why you need to implement IP address matching in > save handler? To prevent session fixation? Doesn't matter, I was just giving you an example. Cheers, Andrey.

« previous php.internals (#81104) next »