HTTP_Session - DB container

From: Date: Mon, 30 Jun 2003 12:28:54 +0000
Subject: HTTP_Session - DB container
Groups: php.pear.dev 
Request: Send a blank email to pear-dev+get-17860@lists.php.net to get a copy of this message
Hi all, im not sure, but seems like there is a bug in HTTP_Session in DB container Lets say we have php.ini 'maxlifetime' 24 minutes 1. Create new session. 2. Add some data to session 3. After 25 min, if we try to change session data, we cant (unless garbage collection is started - but chancee for it is 1/100 or smth like this) why ? 1. data can be changed in write() 2. there are 2 sql UDPATE queries 3. those UPDATE queries end with 'AND expiry >= %d', so session data will never be changed, cause it has expired. It has to wait for garbage collection, to add any new data to session. Below is the code: read(): 'SELECT data FROM %s WHERE id = %s AND expiry >= %d' write(): //IF data not changed 'UPDATE %s SET expiry = %d WHERE id = %s AND expiry >= %d' //ELSE //check if row already exist 'SELECT COUNT(id) FROM %s WHERE id = %s' //insert new 'INSERT INTO %s (id, expiry, data) VALUES (%s, %d, %s)' //update 'UPDATE %s SET expiry = %d, data = %s WHERE id = %s AND expiry >= %d' It should be done smth like this (erase data if session is expired): read(): 'SELECT data,expiry FROM %s WHERE id = %s' if ($expiry < time()) { $data = ''; "UPDATE %s SET expiry = %d, data = '' WHERE id = %s" } and in write() in both update queries ' AND expiry >= %d' can be removed -- cagrET

« previous php.pear.dev (#17860) next »