note 24611 added to function.session-register

From: Date: Thu, 22 Aug 2002 23:23:44 +0000
Subject: note 24611 added to function.session-register
Groups: php.notes 
Request: Send a blank email to php-notes+get-35389@lists.php.net to get a copy of this message
Contrary to the instructions presented in this section, session_register works as follows: Firstly, session_start() either creates a new session, or it hooks up to an existing session by the same name and imports ALL the session variables that are stored in the session from a previous script. This has the affect of overwriting any regular variables of the same name that may exist at the time session_start() is called. For this reason, it should be called at the top of EVERY script to enforce script security. Any session variables that get imported into the script with the session_start() call are imported as regular global variables. They will not be re-exported again when the script ends unless they are again made into session variables. This is done with the session_register() function. session_register('varname') will either create a "session" variable called "varname", or it will convert an existing global variable called "varname" to now be a session variable. session_register() DOES NOT register the value of the variable at all, but it merely flags the variable as having session scope. Only those variables that are registered when the script ends will be written out. This will happen regardless of where the session_register() call is made in the script. By registering all session variables at the top of each script, immediately after the session_start() call, you minimize the possibility of inadvertantly failing to register variables because of an "exit" call that gets made somewhere in the middle of the script. In essence, you ensure everything that needs to get written out, does! Also, if you are using HTML frames and sessions together, you will run into the fact that only one process can access the vars of a session at a time, causing the frames to load sequentially. This can be minimized by using the session_write_close() function. You can call this in your script once you are done making any changes to your session variables, thereby forcing the vars to get exported, and the session to be closed. This will release the session for another frame to continue processing. This is also another reason why session_register() calls should be made at the top of every script. -- http://www.php.net/manual/en/function.session-register.php http://master.php.net/manage/user-notes.php?action=edit+24611 http://master.php.net/manage/user-notes.php?action=delete+24611 http://master.php.net/manage/user-notes.php?action=reject+24611

« previous php.notes (#35389) next »