Re: Fixing halfway implemented session management - timestamp based session management OR remove session_regenerate_id()

From: Date: Sun, 25 Sep 2016 22:12:50 +0000
Subject: Re: Fixing halfway implemented session management - timestamp based session management OR remove session_regenerate_id()
References: 1 2  Groups: php.internals 
Request: Send a blank email to internals+get-96142@lists.php.net to get a copy of this message
> On Sep 25, 2016, at 16:40, Thomas Bley <mails@thomasbley.de> wrote: > > why not have a new session module? those who want no change for existing applications keep the > old one, new projects can use the new one, those who want more security port their code to the new > one. e.g. use session2_start(), etc. If that's going to be the approach (and I find it appealing) then perhaps there should be other things accomplished as part of the new work; e.g., disable the automatic sending of cookie headers and make it explicit. Or wrap all the features in objects. (I don't want to volunteer anyone else for more work, though, and I myself am not competent to implement those ideas.) -- Paul M. Jones http://paul-m-jones.com

« previous php.internals (#96142) next »