Re: [RFC][VOTE] Session ID without hashing
| From: | Derick Rethans | Date: | Thu, 07 Jul 2016 12:32:06 +0000 |
| Subject: | Re: [RFC][VOTE] Session ID without hashing | ||
| References: | 1 2 3 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-94411@lists.php.net to get a copy of this message | ||
On Sat, 2 Jul 2016, Leigh wrote:
> Your patch updates session.use_strict_mode from 0 to 1. I actually don't
> know what this changes, but it's an undocumented change.
http://php.net/manual/en/session.configuration.php#ini.session.use-strict-mode
session.use_strict_mode specifies whether the module will use strict
session id mode. If this mode is enabled, the module does not accept
uninitialized session ID. If uninitialized session ID is sent from
browser, new session ID is sent to browser. Applications are protected
from session fixation via session adoption with strict mode. Defaults to
0 (disabled).