Detailed explanation of session time setting in php
1. The client does not prohibit Cookie
(1) Use session_set_cookie_params() to set the Session expiration time. This function is the Session combined with Cookie to set the expiration time. If you want the Session to expire after one minute, the code example is as follows:
<?php $time = 1*60; //设置session失效时间 session_set_cookie_params($time); // 使用函数 session_start(); //初始化 session $_SESSION["username"] = 'tom'; ?>
Note: session_set_cookie_params() must be called before session_start().
Note: This function is not recommended and may cause problems on some browsers. Therefore, the expiration time is generally set manually.
Related topic recommendations: php session (including pictures, videos, cases)
(2) Use setcookie The () function can set the expiration time for the Session. To make the Session expire after one minute, the code example is as follows:
<?php session_start(); // session失效时间 $time = 1*60; // 使用 setcookie 手动设置 session失效时间 setcookie(session_name(),session_id(),time()+$time.'/'); $_SESSION["username"] = 'tom'; ?>
Description: In the setcookie() function of the above example code, session_name is the name of the Session. , session_id is the identification of the client user, because session_id is a randomly generated unique name, so Session is relatively safe. The expiration time is the same as that of Cookie. The last parameter is optional and is the path where the Cookie is placed.
2. Disabling Cookies on the client
When the client disables Cookies, the transfer between Session pages will be invalid. You can imagine that disabling Cookies on the client is like a large supermarket chain. , if you apply for a membership card in one of the supermarkets, but there is no Internet connection between the supermarkets, the membership card can only be used in the supermarket where you applied. There are several ways to solve this problem:
(1) Remind users that cookies must be turned on before logging in. This is the practice of many forums.
(2) Set session.use_trans_sid =1 in the php.ini file, or turn on the -enable-trans-sid option when compiling to let PHP automatically pass session_id across pages.
(3) Pass the session_id in the hidden form through the GET method.
(4) Use a file or database to store session_id, and call it manually during transfer between pages.
The second method above will not be introduced in detail because users cannot modify the php.ini file in the server. In the third method, we cannot use Cookie to set the expiration time, but the login status does not change. The fourth and most important one can be used if you encounter session files that slow down the server when developing enterprise-level websites. Here we introduce the third method of transmission using the GET method. The sample code is as follows. The code for receiving the page header:
<?php $session_name = session_name(); //取得 session 名称 $session_id = $_GET[$session_name]; // 取得 session_id GET方式 session_id($session_id); // 关键步骤 session_start(); $_SESSION['admin'] = 'soft'; ?>
Description: Session will generate a session_id after requesting the page. If this is If Cookie is disabled, the session_id cannot be passed. When requesting the next page, a session_id will be regenerated, which will cause the session to fail to be passed between pages.
Recommended tutorial: "PHP Tutorial》
The above is the detailed content of How to set session time in php. For more information, please follow other related articles on the PHP Chinese website!

The article compares ACID and BASE database models, detailing their characteristics and appropriate use cases. ACID prioritizes data integrity and consistency, suitable for financial and e-commerce applications, while BASE focuses on availability and

The article discusses securing PHP file uploads to prevent vulnerabilities like code injection. It focuses on file type validation, secure storage, and error handling to enhance application security.

Article discusses best practices for PHP input validation to enhance security, focusing on techniques like using built-in functions, whitelist approach, and server-side validation.

The article discusses strategies for implementing API rate limiting in PHP, including algorithms like Token Bucket and Leaky Bucket, and using libraries like symfony/rate-limiter. It also covers monitoring, dynamically adjusting rate limits, and hand

The article discusses the benefits of using password_hash and password_verify in PHP for securing passwords. The main argument is that these functions enhance password protection through automatic salt generation, strong hashing algorithms, and secur

The article discusses OWASP Top 10 vulnerabilities in PHP and mitigation strategies. Key issues include injection, broken authentication, and XSS, with recommended tools for monitoring and securing PHP applications.

The article discusses strategies to prevent XSS attacks in PHP, focusing on input sanitization, output encoding, and using security-enhancing libraries and frameworks.

The article discusses the use of interfaces and abstract classes in PHP, focusing on when to use each. Interfaces define a contract without implementation, suitable for unrelated classes and multiple inheritance. Abstract classes provide common funct


Hot AI Tools

Undresser.AI Undress
AI-powered app for creating realistic nude photos

AI Clothes Remover
Online AI tool for removing clothes from photos.

Undress AI Tool
Undress images for free

Clothoff.io
AI clothes remover

AI Hentai Generator
Generate AI Hentai for free.

Hot Article

Hot Tools

Zend Studio 13.0.1
Powerful PHP integrated development environment

SublimeText3 English version
Recommended: Win version, supports code prompts!

Dreamweaver CS6
Visual web development tools

MantisBT
Mantis is an easy-to-deploy web-based defect tracking tool designed to aid in product defect tracking. It requires PHP, MySQL and a web server. Check out our demo and hosting services.

VSCode Windows 64-bit Download
A free and powerful IDE editor launched by Microsoft