Sessions
| session_start | |
| Store in | |
| Regenerate id | |
| Logout and destroy |
session_start
A session keeps data on the server across page loads, keyed by a random id stored in a cookie.
Call session_start before any output on every page that needs the session.
Background in
PHP sessions.
After the call the $_SESSION array is ready for reading and writing.
session_start(); echo session_id();
Store in $_SESSION
Treat $_SESSION like a per user storage bag. Save the user id, locale,
and flash messages there instead of passing them through URLs and hidden fields.
Store minimal values and reload the rest from the database on each request.
session_start(); $_SESSION["user_id"] = 42; $_SESSION["locale"] = "en"; echo $_SESSION["user_id"];
Regenerate id
Fixation attacks reuse a known session id, so change the id at privilege boundaries.
Regenerate right after a successful login and before showing account pages.
The data stays, only the id changes, which drops the old id from future use.
session_start(); $_SESSION["user_id"] = 42; session_regenerate_id(true); echo "login complete";
Logout and destroy
A correct logout clears the data, removes the session cookie, and destroys the server side record.
All three steps matter, otherwise a stale id may remain valid.
Redirect to a public page after logout so a refresh cannot resubmit the action.
session_start(); $_SESSION = []; session_destroy(); echo "logged out";
Next: Login with sessions
Article author: Arthur Isaev