note 34933 added to function.session-regenerate-id

From: Date: Tue, 12 Aug 2003 14:46:29 +0000
Subject: note 34933 added to function.session-regenerate-id
Groups: php.notes 
Request: Send a blank email to php-notes+get-54013@lists.php.net to get a copy of this message
After some further experimentation with session_regenerate_id() and cookies, I've discovered that caution should be exercised if your application loads into multiple frames or refreshes the page very quickly. This is simply because some browsers load items in different orders and parse the cookie header data at different times than others, so an application that works on one browser or platform may retain the wrong cookie (and therefore lose all of your session data) on another. I wouldn't recommend the method posted below unless you are certain that you're targetting a single browser and platform, or you have designed the page so that only one frame/window ever calls session_regenerate_id(), and it does not do so more than about once per second. Also, if you do use the method below it's a good idea to keep your temporary directory clean by unlinking the old session files: $oldID = session_id(); session_regenerate_id(); unlink(session_save_path() . "/sess_$oldID"); Insert this where you would normally have inserted session_regenerate_id(). (The format "/sess_$oldID" should work on most platforms, but it would be a good idea to double-check that your version of PHP saves its sessions in this format.) ---- Manual Page -- http://www.php.net/manual/en/function.session-regenerate-id.php Edit Note -- http://master.php.net/manage/user-notes.php?action=edit+34933 Delete Note -- http://master.php.net/manage/user-notes.php?action=delete+34933&report=yes Reject Note -- http://master.php.net/manage/user-notes.php?action=reject+34933&report=yes

« previous php.notes (#54013) next »