note 22961 deleted from function.session-id by sniper
| From: | sniper@php.net | Date: | Wed, 05 Feb 2003 00:11:54 +0000 |
| Subject: | note 22961 deleted from function.session-id by sniper | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-43419@lists.php.net to get a copy of this message | ||
SUBJECT: CREATION OF TRANSACTION ID(GUID) THROUGH SESSION_ID FUNCTION AND SESSION VARIABLES
Comment #1. Assign unique ID for session_id
e.g.
session_id(md5(uniqid(rand(),1)));
session_start();
$TRANSACTION_ID=session_id();
BUT, once the browser has been refreshed, it creates new instance of session id (of course new
instance of transaction ID).
Comment #2. TRANSACTION ID AS session_id(); if you want to create new instance of session ID, after
unsetting and destroying the session variables, you need to add
"setcookie("PHPSESSID","","","/","");"
in order to delete cookie(if cookie enabled), or else old value of session_id will be retained once
the session_id function is called.
e.g.
//create first instance of session and assigning array variables
--start of script #1 (new.php)------------------------------
session_start();
session_register('SESSION');
if (!isset($SESSION)) {
$SESSION = array();
$SESSION['trn_id32'] = strtoupper(session_id());
}
echo "SES ID= " . session_id();
echo "TRN ID= " . $SESSION['trn_id32'];
echo "<a href=\"logout.php\">logout</a>";
--end of script #1------------------------------------------
OUTPUT:
SES ID= 703e05a593bb95d0b37e78b67160a7f8
TRN ID= 703E05A593BB95D0B37E78B67160A7F8
logout
//unset and destroy session
--start of script #2 (logout.php)---------------------------
session_start();
session_unset();
session_destroy();
setcookie("PHPSESSID","","","/","");
echo "SES ID= " . session_id();
echo "TRN ID= " . $SESSION['trn_id32'];
echo "<a href=\"new.php\">new instance</a>";
--end of script #2------------------------------------------
OUPUT:
SES ID=
TRN ID=
--> try session_unregister() function if you want to delete specific session variable
Comment #3. THE SAFIEST WAY IS TO ASSIGN ID TO SESSION VARIABLE
e.g.
session_start();
if (!isset($SESSION)){
$SESSION = array();
$SESSION['trn_id32'] = md5(uniqid(rand(),1));
}
$TRANSACTION_ID=$SESSION['trn_id32'];
--> reset the value of "$SESSION['trn_id32']" by
1. Assign new value of 32 bit transaction id through md5
2. Try to use session_unregister('trn_id32') OR session_unset()[which unset all session
variables], and session_destroy()[destroy all session data]
-dabeast
20020705-171216-PH +0800
"dance like no one's watching"