Newsgroups: php.internals Path: news.php.net Xref: news.php.net php.internals:71545 Return-Path: Mailing-List: contact internals-help@lists.php.net; run by ezmlm Delivered-To: mailing list internals@lists.php.net Received: (qmail 24717 invoked from network); 25 Jan 2014 02:21:52 -0000 Received: from unknown (HELO lists.php.net) (127.0.0.1) by localhost with SMTP; 25 Jan 2014 02:21:52 -0000 Authentication-Results: pb1.pair.com header.from=ajf@ajf.me; sender-id=pass Authentication-Results: pb1.pair.com smtp.mail=ajf@ajf.me; spf=pass; sender-id=pass Received-SPF: pass (pb1.pair.com: domain ajf.me designates 198.187.29.247 as permitted sender) X-PHP-List-Original-Sender: ajf@ajf.me X-Host-Fingerprint: 198.187.29.247 imap4-3.ox.registrar-servers.com Received: from [198.187.29.247] ([198.187.29.247:37399] helo=imap4-3.ox.registrar-servers.com) by pb1.pair.com (ecelerity 2.1.1.9-wez r(12769M)) with ESMTP id 0C/82-11879-FBF13E25 for ; Fri, 24 Jan 2014 21:21:52 -0500 Received: from localhost (localhost [127.0.0.1]) by oxmail.registrar-servers.com (Postfix) with ESMTP id 93D15560075; Fri, 24 Jan 2014 21:21:47 -0500 (EST) X-Virus-Scanned: Debian amavisd-new at imap4.ox.registrar-servers.com Received: from oxmail.registrar-servers.com ([127.0.0.1]) by localhost (imap4.ox.registrar-servers.com [127.0.0.1]) (amavisd-new, port 10024) with LMTP id pTDD_lID2Qve; Fri, 24 Jan 2014 21:21:47 -0500 (EST) Received: from [192.168.0.200] (unknown [176.25.177.94]) (using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by oxmail.registrar-servers.com (Postfix) with ESMTPSA id 38E0E56007B; Fri, 24 Jan 2014 21:21:45 -0500 (EST) Message-ID: <52E31FB6.9010408@ajf.me> Date: Sat, 25 Jan 2014 02:21:42 +0000 User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:24.0) Gecko/20100101 Thunderbird/24.2.0 MIME-Version: 1.0 To: Andrey Andreev , "internals@lists.php.net" References: In-Reply-To: Content-Type: text/plain; charset=UTF-8; format=flowed Content-Transfer-Encoding: 7bit Subject: Re: [PHP-DEV] Session IP address matching From: ajf@ajf.me (Andrea Faulds) On 25/01/14 01:11, Andrey Andreev wrote: > Yes, one can write a custom session handler, but there's a number of > problems with that: Correct me if I'm wrong, but why would you need to do that? Surely, this would suffice: if (!isset($_SESSION['ip'])) { $_SESSION['ip'] = $_SERVER['REMOTE_ADDR']; } else if ($_SERVER['REMOTE_ADDR'] !== $_SESSION['ip']) { session_destroy(); } -- Andrea Faulds http://ajf.me/