note 33550 deleted from function.session-destroy by sniper
| From: | sniper@php.net | Date: | Fri, 17 Oct 2003 05:17:21 +0000 |
| Subject: | note 33550 deleted from function.session-destroy by sniper | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-58742@lists.php.net to get a copy of this message | ||
Note Submitter: simon at studio24.net
----
if you're using superglobals you shouldn't be using session_unregister() to unset session
variables - see http://www.php.net/session
To effectively destroy a session pre PHP 4.1 with Register Globals ON:
function killSession()
{
// you have to unset each session variable one by one
$session_array = explode(";",session_encode());
for ($x = 0; $x < count($session_array); $x++) {
$name = substr($session_array[$x], 0, strpos($session_array[$x], "|"));
if (session_is_registered($name)) {
session_unregister('$name');
}
}
if (!empty(session_encode())) {
return session_destroy();
} else {
return FALSE;
}
}
For those of us with Superglobals and Register Globals OFF it's really simple (as the manual
points out):
function killSession()
{
$_SESSION = array();
return @session_destroy();
}
Both the above functions return TRUE or FALSE
As far as destroying the session ID goes if you have PHP 4.3.2+ use session_regenerate_id() to
create a new session ID for the new session. Otherwise neoh's code works well.