Re: Re: Bug #69127 session_regenerate_id(true) randomly generates a warning and loses session data
| From: | Yasuo Ohgaki | Date: | Tue, 03 Mar 2015 18:21:37 +0000 |
| Subject: | Re: Re: Bug #69127 session_regenerate_id(true) randomly generates a warning and loses session data | ||
| References: | 1 2 3 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-84259@lists.php.net to get a copy of this message | ||
Hi Andrey,
On Tue, Mar 3, 2015 at 7:40 PM, Andrey Andreev <narf@devilix.net> wrote:
> Why do you want to change it at all? If you don't want the data to get
> immediately deleted, pass FALSE to the function and let the GC erase
> it later.
>
It's not precise at all. Old session data that must be deleted could exists
as long as it is accessed. i.e. Stolen session could exists as long as
attacker accesses it.
Timestamping is the method. It's the same as I proposed before.
Regards,
--
Yasuo Ohgaki
yohgaki@ohgaki.net