Session]
Unless a variable is registered using session_register () or $ _ Session.
Otherwise, no session record is automatically added no matter whether session_start () is used or not.
Including resource variables or cyclically referenced objects that point to their own referenced objects and cannot be saved in sessions.
The register_globals command affects the storage and recovery of session variables.
Session. save_handler = "Files"
The name of the processor that stores and retrieves the data associated with the session. The default value is file ("Files ").
If you want to use a custom processor (such as a database-based Processor), you can use "user ".
There is a PostgreSQL processor: http://sourceforge.net/projects/phpform-ext/
Session. save_path = "/tmp"
Parameter passed to the storage processor. For the files processor, this value is the path for creating the session data file.
In Windows, the path of the Temporary Folder is used by default.
You can use "N; [mode;]/path" to define the path (N is an integer ).
; N indicates that sub-directories with N-layer depth are used, instead of saving all data files in one directory.
; [Mode;] (optional) It must use an octal number. The default value is 600 (= 384), indicating the maximum number of session files saved in each directory.
This is a good idea to Improve the Performance of a large number of sessions.
Note: The double quotation marks on both sides of "N; [mode;]/path" cannot be omitted.
; Note 1: [mode;] does not rewrite the umask of the process.
NOTE 2: php does not automatically create these folder structures. Use the mod_files.sh script in the EXT/Session Directory to create the file.
NOTE 3: If the folder can be accessed by insecure users (such as the default "/tmp"), security vulnerabilities may occur.
; NOTE 4: automatic garbage collection fails when n> 0. For details, see the following section on garbage collection.
Session. Name = "PHPSESSID"
The session ID used in the cookie. It can only contain letters and numbers.
Session. auto_start = off
The session is automatically initialized when the customer accesses any page, which is disabled by default.
Because the class definition must be loaded before the session starts, you cannot store objects in the session if this option is enabled.
Session. serialize_handler = "php"
; Is Used to serialize/deserialize data. PHP is a standard serialization/deserialization processor.
You can also use "php_binary ". When wddx support is enabled, only "wddx" can be used ".
Session. gc_probability = 1
Session. gc_divisor = 100
Defines the probability of starting the garbage collection program each time a session is initialized.
The formula for calculating the collection probability is as follows: Session. gc_probability/session. gc_divisor
The more frequently a session page is accessed, the smaller the probability is. Recommended Value: 1/1000 ~ 5000.
Session. gc_maxlife time = 1440
When the number of seconds specified by this parameter is exceeded, the stored data will be treated as 'spam 'and cleared by the garbage collection program.
The criterion is the time when the data is last accessed (for the FAT file system, the time when the data is last refreshed ).
If multiple scripts share the same session. save_path directory but session. gc_maxlifetime is different,
The minimum value in all session. gc_maxlifetime commands prevails.
If multi-layer sub-directories are used to store data files, the garbage collection program will not start automatically.
You must use a shell script, cron item, or other method you have compiled to perform garbage collection.
For example, the following script is equivalent to setting "session. gc_maxlifetime = 1440" (24 minutes ):
; CD/path/to/sessions; find-Cmin + 24 | xargs RM
Session. referer_check =
If the "Referer" field in the Request Header does not contain the specified string, the session ID is considered invalid.
Note: If the "Referer" field does not exist in the request header, the session ID will still be considered valid.
; The default value is null, that is, no check is performed (all are considered valid ).
Session. entropy_file =; "/dev/urandom"
; Additional external high-entropy resources (Files) used to create session IDs ),
For example, "/dev/random" or "/dev/urandom" On Unix systems"
Session. entropy_length = 0
; The number of bytes read from resources with high entropy (Recommended Value: 16 ).
Session. use_cookies = on
Whether to use the cookie to save the session ID on the client
Session. use_only_cookies = off
; Whether to only use cookies to save session IDs on the client
; Enable this option to avoid the security issues caused by passing sessions through URLs.
However, the client that disables the cookie will make the session unable to work.
Session. cookie_lifetime = 0
The cookie validity period (in seconds) for passing session IDs. 0 indicates that the cookie is valid only when the browser opens.
Session. cookie_path = "/"
The path of the cookie that transmits the session ID.
Session. cookie_domain =
The cookie scope for passing session IDs.
The default value is null, indicating the host name generated according to the cookie specification.
Session. cookie_secure = off
; Whether to send cookies only through secure connections (https.
Session. cookie_httponly = off
; Whether to add the HTTPOnly flag to the cookie (only HTTP protocol access is allowed ),
; This will cause client scripts (JavaScript, etc.) to be unable to access the cookie.
To effectively prevent session IDs from being hijacked through XSS attacks.
Session. cache_limiter = "nocache"
; Set to {nocache | private | public} to specify the Cache Control Mode of the session page,
Or leave it blank to prevent the HTTP Response Header from sending commands that disable caching.
Session. cache_expire = 180
; Specify the validity period of the session page in the Client Cache (minutes)
; Session. cache_limiter = nocache, the setting here is invalid.
Session. use_trans_sid = off
Whether to use the plaintext to display the SID (session ID) in the URL ).
It is disabled by default because it brings security risks to your users:
; 1-The user may include a valid Sid URL via email/IRC/QQ/MSN... The channel is told to others.
; 2-a URL containing a valid Sid may be saved on a public computer.
3-users may save URLs with fixed Sid in their favorites or browsing history records.
URL-based session management is always more risky than cookie-based session management, so it should be disabled.
Session. bug_compat_42 = on
Session. bug_compat_warn = on
In versions earlier than php4.2, there is an unspecified "bug ":
; The Global session variable can be initialized even if register_globals is off,
If you use this feature in Versions later than php4.3, a warning is displayed.
You are advised to close the bug and display a warning.
Session. hash_function = 0
Generate the hash algorithm for Sid. SHA-1 is more secure.
; 0: MD5. (128 bits)
; 1: SHA-1 (160 bits)
SHA-1 is recommended.
Session. hash_bits_per_character = 4
; Specifies the number of bits in each character in the SID string,
; These binary numbers are the calculation results of the hash function.
; 4: 0-9, A-F
; 5: 0-9, A-V
; 6: 0-9, A-Z, A-Z ,"-",","
Recommended Value: 5
Url_rewriter.tags = "A = href, Area = href, frame = SRC, form =, fieldset ="
This command is a core part of PHP and does not belong to the session module.
; Specifies which HTML tags to override to include Sid (only valid when session. use_trans_sid = on)
Form and fieldset are special:
If you include them, the URL writer adds a hidden "<input>", which contains information that should be appended to the URL.
To comply with the XHTML standard, remove the form item and add the <fieldset> mark before and after the form field.
Note: All valid items require an equal sign (even if there is no value ).
The recommended value is "A = href, Area = href, frame = SRC, input = SRC, form = fakeentry ".