note 81354 deleted from function.session-regenerate-id by jani
| From: | jani@php.net | Date: | Wed, 16 Sep 2009 12:17:23 +0000 |
| Subject: | note 81354 deleted from function.session-regenerate-id by jani | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-160612@lists.php.net to get a copy of this message | ||
Note Submitter: brent5392 at gmail dot com
----
I am unsure if this is a bug, or just some weird result. I cannot check if this has changed/or has
been fixed in a latest snapshot as I do not have the required resources to do so. I do know that
this problem does occur in the lastest stable release of PHP5.
When using session_regenerate_id() and session_set_cookie_params() together the domain in
session_set_cookie_params MUST be exact.
You cannot have: ".example.com" so that cookies may be used accross sub domains.
It must be exact: "sub.example.com".
If you do not enter a full domain, when calling session_regenerate_id() it will change the session
id for ONLY that executiong. Any other pages will still contain the old session id. In a way, it
creates a temporary session that only last until that script finishes executing.
In reply to: Gant at BleachEatingFreaks dot com
Your result was the same as mine. I was having the same problem. It took me hours to find the exact
cause of the problem.