Re: Re: [RFC][VOTE] Session ID without hashing - Vote reopened and restarted

From: Date: Thu, 04 Aug 2016 08:11:08 +0000
Subject: Re: Re: [RFC][VOTE] Session ID without hashing - Vote reopened and restarted
References: 1 2 3  Groups: php.internals 
Request: Send a blank email to internals+get-94823@lists.php.net to get a copy of this message
Hi all and Davey, On Wed, Aug 3, 2016 at 4:36 PM, Davey Shafik <davey@php.net> wrote: > > Unfortunately this missed beta2 (tagged yesterday), I'll confirm with Joe > about putting it in for 7.1beta3. > > Thanks for those last minute changes, I'm much happier with this result! :) I just realized, php.ini-development/production uses session.hash_func=0 session.hash_bits_per_character=5 (Compiled default is 4) The session ID will be ^[0-9a-v]{26}$ (length=26 chars) So I'll modify php.ini-* default to session.sid_length=26 session.sid_bit_per_character=5 This matches the current default session ID format used widely. Sorry for the confusions, but compatible should mean compatible with current default. Regards, P.S. Davery, should I push the patch to 7.1 and master branch, or you will? I don't mind pasting the patch for 7.1 branch to gist. -- Yasuo Ohgaki yohgaki@ohgaki.net

« previous php.internals (#94823) next »