不同浏览器session_id相同的可能性????
session_id重复 session cookie
我一直知道的是session_id绝对唯一。但在做一个二级域名的session共享的时候,发现一个问题:用户第一次访问时,将session_id保存到cookie,cookie有效期设置为一天,然后用户退出。在30分钟后,服务器的session被销毁,而此时用户携带被保存在cookie的session_id访问。。在服务器端,为了二级域名共享session_id,做了一个判断:只要存在$_COOKIE['session_id'],就使用session_id()函数直接访问服务器的session。。
那么问题就出现了,此时用户传递的session_id,对应的session已经被销毁了。那么此时服务器是否可能存在一个session,它的session_id恰好是用户传递的$_COOKIE['session_id']呢???
注:服务器销毁session后,自然会忽略掉该session对应的session_id。那么也就可能服务器再次生成这个session_id分配给另外的session。
求大礼赐教,不胜感激!!!!!
回复讨论(解决方案)
session_id 是一个与时间相关的值,只要地球还在转,就不会出现重复
时间是递增的值,所以已经过去的时间不可能在将来出现。但是session_id不是字母+数字的字符串吗,从排列组合上来说也存在重复的可能性啊??
session_id 是一个与时间相关的值,只要地球还在转,就不会出现重复
每微秒产生一个数,8字节大约可以使用100年,一百年后电脑还是电脑吗?

Hot AI Tools

Undresser.AI Undress
AI-powered app for creating realistic nude photos

AI Clothes Remover
Online AI tool for removing clothes from photos.

Undress AI Tool
Undress images for free

Clothoff.io
AI clothes remover

Video Face Swap
Swap faces in any video effortlessly with our completely free AI face swap tool!

Hot Article

Hot Tools

Notepad++7.3.1
Easy-to-use and free code editor

SublimeText3 Chinese version
Chinese version, very easy to use

Zend Studio 13.0.1
Powerful PHP integrated development environment

Dreamweaver CS6
Visual web development tools

SublimeText3 Mac version
God-level code editing software (SublimeText3)

Hot Topics

Alipay PHP...

JWT is an open standard based on JSON, used to securely transmit information between parties, mainly for identity authentication and information exchange. 1. JWT consists of three parts: Header, Payload and Signature. 2. The working principle of JWT includes three steps: generating JWT, verifying JWT and parsing Payload. 3. When using JWT for authentication in PHP, JWT can be generated and verified, and user role and permission information can be included in advanced usage. 4. Common errors include signature verification failure, token expiration, and payload oversized. Debugging skills include using debugging tools and logging. 5. Performance optimization and best practices include using appropriate signature algorithms, setting validity periods reasonably,

Session hijacking can be achieved through the following steps: 1. Obtain the session ID, 2. Use the session ID, 3. Keep the session active. The methods to prevent session hijacking in PHP include: 1. Use the session_regenerate_id() function to regenerate the session ID, 2. Store session data through the database, 3. Ensure that all session data is transmitted through HTTPS.

The application of SOLID principle in PHP development includes: 1. Single responsibility principle (SRP): Each class is responsible for only one function. 2. Open and close principle (OCP): Changes are achieved through extension rather than modification. 3. Lisch's Substitution Principle (LSP): Subclasses can replace base classes without affecting program accuracy. 4. Interface isolation principle (ISP): Use fine-grained interfaces to avoid dependencies and unused methods. 5. Dependency inversion principle (DIP): High and low-level modules rely on abstraction and are implemented through dependency injection.

How to debug CLI mode in PHPStorm? When developing with PHPStorm, sometimes we need to debug PHP in command line interface (CLI) mode...

How to automatically set the permissions of unixsocket after the system restarts. Every time the system restarts, we need to execute the following command to modify the permissions of unixsocket: sudo...

Static binding (static::) implements late static binding (LSB) in PHP, allowing calling classes to be referenced in static contexts rather than defining classes. 1) The parsing process is performed at runtime, 2) Look up the call class in the inheritance relationship, 3) It may bring performance overhead.

Sending JSON data using PHP's cURL library In PHP development, it is often necessary to interact with external APIs. One of the common ways is to use cURL library to send POST�...
