note 33550 deleted from function.session-destroy by sniper

From: Date: Fri, 17 Oct 2003 05:17:21 +0000
Subject: note 33550 deleted from function.session-destroy by sniper
References: 1  Groups: php.notes 
Request: Send a blank email to php-notes+get-58742@lists.php.net to get a copy of this message
Note Submitter: simon at studio24.net ---- if you're using superglobals you shouldn't be using session_unregister() to unset session variables - see http://www.php.net/session To effectively destroy a session pre PHP 4.1 with Register Globals ON: function killSession() { // you have to unset each session variable one by one $session_array = explode(";",session_encode()); for ($x = 0; $x < count($session_array); $x++) { $name = substr($session_array[$x], 0, strpos($session_array[$x], "|")); if (session_is_registered($name)) { session_unregister('$name'); } } if (!empty(session_encode())) { return session_destroy(); } else { return FALSE; } } For those of us with Superglobals and Register Globals OFF it's really simple (as the manual points out): function killSession() { $_SESSION = array(); return @session_destroy(); } Both the above functions return TRUE or FALSE As far as destroying the session ID goes if you have PHP 4.3.2+ use session_regenerate_id() to create a new session ID for the new session. Otherwise neoh's code works well.

« previous php.notes (#58742) next »