note 16598 deleted from function.session-id by jimw
| From: | jimw@php.net | Date: | Wed, 02 Jan 2002 11:37:18 +0000 |
| Subject: | note 16598 deleted from function.session-id by jimw | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-24228@lists.php.net to get a copy of this message | ||
There are times when one MUST create the session_id(). For example, if you session_destroy(), then
2nd session_start() will reuse the pre-existing session_id(), unless you create and set a new one.
Since there is no session_id_new(), we have to simulate it ourself.
[Note: my opinion of the importance of creating a new session id and deleting the old session file
for each page of session is another topic which I covered in the root documentation for sessions.]
Looking at the source code for PHP4.0.6, essentially it creates the session id using:
session_id( md5( uniqid( "", 1 ) ) );
There is some additional bit twiddling on the MD5 result in the source which I don't
understand, and I assume is less essential to the randomness and uniquess criteria:
for (i = 0; i < 16; i++)
sprintf(buf + (i << 1), "%02x", digest[i]);
buf[i << 1] = '\0';