note 22961 deleted from function.session-id by sniper

From: Date: Wed, 05 Feb 2003 00:11:54 +0000
Subject: note 22961 deleted from function.session-id by sniper
References: 1  Groups: php.notes 
Request: Send a blank email to php-notes+get-43419@lists.php.net to get a copy of this message
SUBJECT: CREATION OF TRANSACTION ID(GUID) THROUGH SESSION_ID FUNCTION AND SESSION VARIABLES Comment #1. Assign unique ID for session_id e.g. session_id(md5(uniqid(rand(),1))); session_start(); $TRANSACTION_ID=session_id(); BUT, once the browser has been refreshed, it creates new instance of session id (of course new instance of transaction ID). Comment #2. TRANSACTION ID AS session_id(); if you want to create new instance of session ID, after unsetting and destroying the session variables, you need to add "setcookie("PHPSESSID","","","/","");" in order to delete cookie(if cookie enabled), or else old value of session_id will be retained once the session_id function is called. e.g. //create first instance of session and assigning array variables --start of script #1 (new.php)------------------------------ session_start(); session_register('SESSION'); if (!isset($SESSION)) { $SESSION = array(); $SESSION['trn_id32'] = strtoupper(session_id()); } echo "SES ID= " . session_id(); echo "TRN ID= " . $SESSION['trn_id32']; echo "<a href=\"logout.php\">logout</a>"; --end of script #1------------------------------------------ OUTPUT: SES ID= 703e05a593bb95d0b37e78b67160a7f8 TRN ID= 703E05A593BB95D0B37E78B67160A7F8 logout //unset and destroy session --start of script #2 (logout.php)--------------------------- session_start(); session_unset(); session_destroy(); setcookie("PHPSESSID","","","/",""); echo "SES ID= " . session_id(); echo "TRN ID= " . $SESSION['trn_id32']; echo "<a href=\"new.php\">new instance</a>"; --end of script #2------------------------------------------ OUPUT: SES ID= TRN ID= --> try session_unregister() function if you want to delete specific session variable Comment #3. THE SAFIEST WAY IS TO ASSIGN ID TO SESSION VARIABLE e.g. session_start(); if (!isset($SESSION)){ $SESSION = array(); $SESSION['trn_id32'] = md5(uniqid(rand(),1)); } $TRANSACTION_ID=$SESSION['trn_id32']; --> reset the value of "$SESSION['trn_id32']" by 1. Assign new value of 32 bit transaction id through md5 2. Try to use session_unregister('trn_id32') OR session_unset()[which unset all session variables], and session_destroy()[destroy all session data] -dabeast 20020705-171216-PH +0800 "dance like no one's watching"

« previous php.notes (#43419) next »