Re: [RFC][VOTE] Add session_create_id() function

From: Date: Thu, 11 Aug 2016 23:20:22 +0000
Subject: Re: [RFC][VOTE] Add session_create_id() function
References: 1 2 3 4  Groups: php.internals 
Request: Send a blank email to internals+get-95054@lists.php.net to get a copy of this message
Hi Leigh, On Fri, Aug 12, 2016 at 8:07 AM, Yasuo Ohgaki <yohgaki@ohgaki.net> wrote: > $encoded = base64_encode(ini_get('session.sid_length')*2); > // Use same charset as PHP > $sid = substr(rtrim(strtr($encoded, '+/', ',-'), '='), 0, > ini_get('session.sid_length'); I've missed to handle session.hash_bits_per_character here. There are people validating SID (used chars and length) via WAF or PHP code. session.hash_bits_per_character handling is mandatory for such system. Implementing things properly and precisely is not easy :) Regards, -- Yasuo Ohgaki yohgaki@ohgaki.net

« previous php.internals (#95054) next »