Re: [RFC][VOTE] Add session_create_id() function
| From: | Yasuo Ohgaki | Date: | Wed, 10 Aug 2016 10:17:52 +0000 |
| Subject: | Re: [RFC][VOTE] Add session_create_id() function | ||
| References: | 1 2 3 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-94996@lists.php.net to get a copy of this message | ||
Hi all,
On Wed, Aug 10, 2016 at 7:03 PM, Yasuo Ohgaki <yohgaki@ohgaki.net> wrote:
> It requires a lot less user code
>
> session_rengenerate_id('myprefix-');
>
> yet it is safe.
I forgot to mention important requirement.
It is safe when 'session.use_strict_mode=1'.
Unfortunately, RFC for enabling use_strict_mode by default
https://wiki.php.net/rfc/session-use-strict-mode
is declined.
--
Yasuo Ohgaki
yohgaki@ohgaki.net