473,387 Members | 1,575 Online
Bytes | Software Development & Data Engineering Community
Post Job

Home Posts Topics Members FAQ

Join Bytes to post your question to a community of 473,387 software developers and data experts.

sessions - two with same session ID as the same time

Hi Folk

I just had a brainwave. I leave a session cookie on someone's machine so
that I recognise them (with their session ID in the cookie) when they come
back, I also offer them the option to have an email sent to their email
address with a link that sets the session ID to the one in the emailed link
so that they can open their account from another computer.

Now, my question is, can you have two users on different computers be on the
website at the same time with the same session ID?
Jan 18 '06 #1
6 2564
d
"windandwaves" <wi*********@coldmail.com> wrote in message
news:ti********************@news.xtra.co.nz...
Hi Folk

I just had a brainwave. I leave a session cookie on someone's machine so
that I recognise them (with their session ID in the cookie) when they come
back, I also offer them the option to have an email sent to their email
address with a link that sets the session ID to the one in the emailed
link so that they can open their account from another computer.

Now, my question is, can you have two users on different computers be on
the website at the same time with the same session ID?


There's nothing to stop you trying it out! Remember, you can use two
different browsers on one machine to simulate two computers for testing
purposes.

If there's a mechanism for logging in, then that's completely unnecessary...
do you have that?

I'm not sure I understand what you're actually trying to achieve ;)
Jan 18 '06 #2
d wrote:
"windandwaves" <wi*********@coldmail.com> wrote in message
news:ti********************@news.xtra.co.nz...
Hi Folk

I'm not sure I understand what you're actually trying to achieve ;)


I guess what I am wondering if it is a (potential) problem if two people are
using the same session ID and if so, what are these problems.

TIA

- Nicolaas
Jan 19 '06 #3
if you are using a login mechanism (mysql, flat-file, whatever) store
this session information where you have control over it - you cannot
rely on the user being on the same computer everytime they access your
site. (ie: home computer, work computer, etc...)

Michael Austin
Consultant

Jan 19 '06 #4
windandwaves wrote:
<snip>
I guess what I am wondering if it is a (potential) problem if two people are
using the same session ID and if so, what are these problems.


Google for session hijacking.

--
<?php echo 'Just another PHP saint'; ?>
Email: rrjanbiah-at-Y!com Blog: http://rajeshanbiah.blogspot.com/

Jan 19 '06 #5
d
"windandwaves" <wi*********@coldmail.com> wrote in message
news:to********************@news.xtra.co.nz...
d wrote:
"windandwaves" <wi*********@coldmail.com> wrote in message
news:ti********************@news.xtra.co.nz...
Hi Folk I'm not sure I understand what you're actually trying to achieve ;)


I guess what I am wondering if it is a (potential) problem if two people
are using the same session ID and if so, what are these problems.


If you use a non-locking session handler (ie no the default file-based
sessions), you'll technically be ok. Whether it's a good idea or not is up
to you ;)
TIA

- Nicolaas

Jan 19 '06 #6
>I guess what I am wondering if it is a (potential) problem if two people are
using the same session ID and if so, what are these problems.


They have the same set of session variables, which they both change.

This can be a problem with, say, a shopping cart application.
You could end up with one frustrated user repeatedly adding
a football jersey and deleting knitting needles, and the other
user repeatedly adding knitting needles and deleting the football
jersey.

Depending on how you handle logouts, if one logs out, it kills the
session for the other one.

If you have a "password change" feature, either user probably ends
up changing the password for both.

If the site has a mailbox feature, they share the same mailbox, read
each other's mail, and send mail from the same identity.

Gordon L. Burditt
Jan 19 '06 #7

This thread has been closed and replies have been disabled. Please start a new discussion.

Similar topics

2
by: Dave Mateer | last post by:
Hi Why does the following code allow me to keep the same session when in the same sub domain (ie admin.localhost), yet not when I goto another related domain eg main.localhost? I would like...
22
by: Theo | last post by:
Question for the group The authentication system for the site Im working on seems to function properly and all is good. A session keeps track of everything and a cookie is used to accept or deny...
1
by: windandwaves | last post by:
Hi Gurus I am basically sorry that I have to bother you about this. I am a PHP beginner and I have been studying sessions and cookies over the last few weeks. I have learned lots, but I am...
9
by: Bartosz Wegrzyn | last post by:
I need help with sessions. I createt set of web site for nav with authorization. first I go into main.php which looks like this: <?php //common functions include_once '../login/common.php';...
3
by: Maxime Ducharme | last post by:
Hi group We have a problem with sessions in one of our sites. Sessions are used to store login info & some other infos (no objects are stored in sessions). We are using Windows 2000 Server...
6
by: Daniel Walzenbach | last post by:
Hi, I have a web application which sometimes throws an “out of memory” exception. To get an idea what happens I traced some values using performance monitor and got the following values (for...
13
by: Simon Dean | last post by:
And while Im at it... should I be using PHP's built in sessions, or use my own functions that I've chobbled together from various sources and takes advantage of also validating IP Addresses??? I...
1
by: Duncan | last post by:
I have a strange problem with sessions in PHP 5. I have a simple script that prints a random number both as a string and a picture on the screen. When I run the script for the first time, it works...
3
by: Jon Slaughter | last post by:
Any pitfalls or stuff I need to worry about when working with sessions? I want to write a log file and hit counter along with a login interface and I'm trying to learn this stuff. ...
3
Atli
by: Atli | last post by:
Introduction: Sessions are one of the simplest and more powerful tools in a web developers arsenal. This tool is invaluable in dynamic web page development and it is one of those things every...
0
by: taylorcarr | last post by:
A Canon printer is a smart device known for being advanced, efficient, and reliable. It is designed for home, office, and hybrid workspace use and can also be used for a variety of purposes. However,...
0
by: ryjfgjl | last post by:
If we have dozens or hundreds of excel to import into the database, if we use the excel import function provided by database editors such as navicat, it will be extremely tedious and time-consuming...
0
by: emmanuelkatto | last post by:
Hi All, I am Emmanuel katto from Uganda. I want to ask what challenges you've faced while migrating a website to cloud. Please let me know. Thanks! Emmanuel
1
by: Sonnysonu | last post by:
This is the data of csv file 1 2 3 1 2 3 1 2 3 1 2 3 2 3 2 3 3 the lengths should be different i have to store the data by column-wise with in the specific length. suppose the i have to...
0
by: Hystou | last post by:
There are some requirements for setting up RAID: 1. The motherboard and BIOS support RAID configuration. 2. The motherboard has 2 or more available SATA protocol SSD/HDD slots (including MSATA, M.2...
0
marktang
by: marktang | last post by:
ONU (Optical Network Unit) is one of the key components for providing high-speed Internet services. Its primary function is to act as an endpoint device located at the user's premises. However,...
0
by: Hystou | last post by:
Most computers default to English, but sometimes we require a different language, especially when relocating. Forgot to request a specific language before your computer shipped? No problem! You can...
0
Oralloy
by: Oralloy | last post by:
Hello folks, I am unable to find appropriate documentation on the type promotion of bit-fields when using the generalised comparison operator "<=>". The problem is that using the GNU compilers,...
0
jinu1996
by: jinu1996 | last post by:
In today's digital age, having a compelling online presence is paramount for businesses aiming to thrive in a competitive landscape. At the heart of this digital strategy lies an intricately woven...

By using Bytes.com and it's services, you agree to our Privacy Policy and Terms of Use.

To disable or enable advertisements and analytics tracking please visit the manage ads & tracking page.