note 8069 added to Session handling functions
| From: | php at apt7 dot com | Date: | Fri, 25 Aug 2000 23:58:53 +0000 |
| Subject: | note 8069 added to Session handling functions | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-3266@lists.php.net to get a copy of this message | ||
It would be nice if the documentation said a little bit more about what PHP session functions do
behind the scenes.
Those of us who want to know how secure session variables are need to know a bit more about this. In
particular, I need to know if session data is stored both on the client *and* the server for every
session. Also, how is the data integrity verified for sessions? That is, does PHP check to make sure
that the values that are in the client-side session variables have not been changed (by a malicious
user altering cookies or query strings)?
As it stands, I will have to do my own data integrity checking on every session page.
Dean.
http://www.php.net/manual/ref.session.php