Session regeneration

I have some confusion with session handling in PHP. I know how to restore a new session identifier in PHP using session_regenerate_id();, but I do not understand why and when I need to restore a new session identifier.

I have been looking for searches on Google for a long time. No one explains why I need to restore a new session id.

Can someone explain why and when I will need to restore the new session identifier?

+3
source share
2 answers

The reason that regenerative sessions are considered good is because it is trying to prevent the session from being committed (or at least to limit the damage).

+4
source
+1

Source: https://habr.com/ru/post/1750349/


All Articles