note 58850 deleted from function.session-destroy by philip
| From: | philip@php.net | Date: | Wed, 29 Mar 2006 06:12:51 +0000 |
| Subject: | note 58850 deleted from function.session-destroy by philip | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-106909@lists.php.net to get a copy of this message | ||
Note Submitter:
----
Running 4.4 under Apache 1.3 under W2K, I'm storing session data in a mysql table. In trying
to completely purge a session for security's sake, using this model as shown above:
?php
session_start(); // restore the session
$_SESSION = array(); // clear the universal var
if (isset($_COOKIE[session_name()])) {
setcookie(session_name(), '', time()-42000, '/');
} // clobber the cookie
session_destroy(); // purge the session record
exit(); // we're done
?>
I find that the final step of purging the session record doesn't work as that example seems to
imply. Something is re-creating "for free" a data-less zombie record under the same
session id immediately after the purge...which, needless to say, is unexpected and disconcerting.