Re: [RFC][VOTE] Add session_create_id() function
| From: | Yasuo Ohgaki | Date: | Thu, 11 Aug 2016 23:20:22 +0000 |
| Subject: | Re: [RFC][VOTE] Add session_create_id() function | ||
| References: | 1 2 3 4 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-95054@lists.php.net to get a copy of this message | ||
Hi Leigh,
On Fri, Aug 12, 2016 at 8:07 AM, Yasuo Ohgaki <yohgaki@ohgaki.net> wrote:
> $encoded = base64_encode(ini_get('session.sid_length')*2);
> // Use same charset as PHP
> $sid = substr(rtrim(strtr($encoded, '+/', ',-'), '='), 0,
> ini_get('session.sid_length');
I've missed to handle session.hash_bits_per_character here. There are
people validating SID (used chars and length) via WAF or PHP code.
session.hash_bits_per_character handling is mandatory for such system.
Implementing things properly and precisely is not easy :)
Regards,
--
Yasuo Ohgaki
yohgaki@ohgaki.net