Session Security manual page is updated
| From: | Yasuo Ohgaki | Date: | Tue, 13 Sep 2016 01:50:13 +0000 |
| Subject: | Session Security manual page is updated | ||
| Groups: | php.doc php.internals | ||
| Request: | Send a blank email to internals+get-95967@lists.php.net to get a copy of this message | ||
Hi all,
I've updated session security manual page a lot.
http://php.net/manual/en/session.security.php
Some of us do not realize importance of non adoptive session
management and timestamp management. e.g.
https://wiki.php.net/rfc/precise_session_management
https://wiki.php.net/rfc/session-use-strict-mode
I've tried to
explain why they are important and mandatory for session security.
Comments, questions, corrections and additions are appreciated!
Current session manager is half broken. I would like to correct
session module behavior in near future.
Regards,
--
Yasuo Ohgaki
yohgaki@ohgaki.net