Re: [PHP4BETA] Docs for sessions?
| From: | Sascha Schumann | Date: | Thu, 22 Jul 1999 00:10:02 +0000 |
| Subject: | Re: [PHP4BETA] Docs for sessions? | ||
| References: | 1 2 3 4 | Groups: | php.version4 |
| Request: | Send a blank email to php-version4+get-2480@lists.php.net to get a copy of this message | ||
On Thu, Jul 22, 1999 at 12:47:53AM +0100, Matthew Clark wrote:
> Sascha Schumann wrote:
>
> > On Tue, Jul 20, 1999 at 10:08:45PM +0200, Sander Pilon wrote:
> > > How about a heap of example code?
> > >
> >
> > Here is a sample script (really simply, more documentation will
> > come).
> >
> > <?php
> >
> > session_register("count");
>
> Are the session variables handled in the same way as ASP
> session vars? i.e. as cookies...
>
> I'm a session ID + Session Database (or similar derivitives)
> advocate. :-) Mainly because cookies have some serious
> pitfalls...
The session module will try to set a cookie on the client side
and, if it's not completely sure that the cookie was set, defines
a constant (sid) to contain "<session-name>=<session-id>".
You should read about the security impacts of the so called get
mode (where you transport session IDs in the URL) in the PHPLIB
mailing list archive. Cookies have some serious advantages when
it comes to security (i.e. they are not logged, not transported
in the HTTP Referer and so on).
--
Regards,
Sascha Schumann
Consultant