note 16598 added to function.session-id

From: Date: Mon, 05 Nov 2001 21:55:18 +0000
Subject: note 16598 added to function.session-id
Groups: php.notes 
Request: Send a blank email to php-notes+get-20499@lists.php.net to get a copy of this message
There are times when one MUST create the session_id(). For example, if you session_destroy(), then 2nd session_start() will reuse the pre-existing session_id(), unless you create and set a new one. Since there is no session_id_new(), we have to simulate it ourself. [Note: my opinion of the importance of creating a new session id and deleting the old session file for each page of session is another topic which I covered in the root documentation for sessions.] Looking at the source code for PHP4.0.6, essentially it creates the session id using: session_id( md5( uniqid( "", 1 ) ) ); There is some additional bit twiddling on the MD5 result in the source which I don't understand, and I assume is less essential to the randomness and uniquess criteria: for (i = 0; i < 16; i++) sprintf(buf + (i << 1), "%02x", digest[i]); buf[i << 1] = '\0'; -- http://www.php.net/manual/en/function.session-id.php http://master.php.net/manage/user-notes.php?action=edit+16598 http://master.php.net/manage/user-notes.php?action=delete+16598 http://master.php.net/manage/user-notes.php?action=reject+16598

« previous php.notes (#20499) next »