note 32962 added to function.unset
| From: | jrshank at earthlink dot net | Date: | Thu, 12 Jun 2003 03:47:36 +0000 |
| Subject: | note 32962 added to function.unset | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-50215@lists.php.net to get a copy of this message | ||
As gabe at mudbuginfo dot com points out in his 15-May-2003 post, there is indeed a bug in using
unset on $_SESSION['variable'] when globals are on. The suggested
unset( $_SESSION['variable'], $variable );
did not work for me in PHP 4.2.3. However, the following did work for me:
unset($_SESSION['$variable'];
session_unregister($variable);
Yes, I know that the docs say not to use session_unregister when you are using $_SESSION, but
practical experience shows that it works.
Here is my theory (completely unverified, but it works out logically). When register globals is set
to on, PHP looks for two things to register sessions in the file. 1) a session_register() function
call OR 2) a new variable in the $_SESSION superglobal. This allows people who write using
superglobals to still have their scripts work whether register globals is on or off. Unfortunately,
when register globals is on, PHP does not check the $_SESSION array to see if any of the variables
that it has written to the session file are now unset. In fact, the only function that actually
removes the session data from the session file (again, when register globals is on) is
session_unregister().
According to this theory, the two steps are necessary because if you simply use
session_unregister(), PHP will simply read the variable in $_SESSION and re-register the variable.
If you simply remove it from the $_SESSION array without running session_unregister(), the removal
has no effect on the session file.
Again, this is simply my theory. I haven't looked at the PHP source code to verify this and I
welcome a confirmation or a correction from someone who has.
----
Manual Page -- http://www.php.net/manual/en/function.unset.php
Edit Note -- http://master.php.net/manage/user-notes.php?action=edit+32962
Delete Note -- http://master.php.net/manage/user-notes.php?action=delete+32962&report=yes
Reject Note -- http://master.php.net/manage/user-notes.php?action=reject+32962&report=yes