RE: Forcing a new Session ID?
| From: | Jon E. Mitchiner | Date: | Tue, 26 Oct 1999 20:16:58 +0000 |
| Subject: | RE: Forcing a new Session ID? | ||
| References: | 1 | Groups: | php.version4 |
| Request: | Send a blank email to php-version4+get-5715@lists.php.net to get a copy of this message | ||
Since nobody replied -- I guess theres no way (at this time) to force
someone to get a new session id?
> Im trying to implement some security routines with the Session ID
> processing so if someone tries hijacking someone else's session
> based on certain variables that fail then they will be forced to
> get a new session id.
>
> Ive been trying to figure this out, but have had no luck. What
> would be the best way to do this -without- destroying the
> existing user's session.
>
> I tried stuff like:
>
> $newsid = md5(rand);
> session_name($newsid); -or- session_id($newsid);
>
> Neither one seems to have any change or affects the session id.
> Suggestions, ideas, etc would be appreciated.
>
> Thanks!
> Jon Mitchiner
> ICQ # 21030881
> AIM # MinotaurT