note 34933 added to function.session-regenerate-id
| From: | dan at danposluns dot com | Date: | Tue, 12 Aug 2003 14:46:29 +0000 |
| Subject: | note 34933 added to function.session-regenerate-id | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-54013@lists.php.net to get a copy of this message | ||
After some further experimentation with session_regenerate_id() and cookies, I've discovered
that caution should be exercised if your application loads into multiple frames or refreshes the
page very quickly.
This is simply because some browsers load items in different orders and parse the cookie header data
at different times than others, so an application that works on one browser or platform may retain
the wrong cookie (and therefore lose all of your session data) on another.
I wouldn't recommend the method posted below unless you are certain that you're targetting
a single browser and platform, or you have designed the page so that only one frame/window ever
calls session_regenerate_id(), and it does not do so more than about once per second.
Also, if you do use the method below it's a good idea to keep your temporary directory clean by
unlinking the old session files:
$oldID = session_id();
session_regenerate_id();
unlink(session_save_path() . "/sess_$oldID");
Insert this where you would normally have inserted session_regenerate_id(). (The format
"/sess_$oldID" should work on most platforms, but it would be a good idea to double-check
that your version of PHP saves its sessions in this format.)
----
Manual Page -- http://www.php.net/manual/en/function.session-regenerate-id.php
Edit Note -- http://master.php.net/manage/user-notes.php?action=edit+34933
Delete Note -- http://master.php.net/manage/user-notes.php?action=delete+34933&report=yes
Reject Note -- http://master.php.net/manage/user-notes.php?action=reject+34933&report=yes