----- Original Message -----
From: "Sterling Hughes" <[EMAIL PROTECTED]>
To: <[EMAIL PROTECTED]>
Cc: <[EMAIL PROTECTED]>
Sent: Tuesday, July 01, 2003 9:51 PM
Subject: Re: [PHP-DEV] Removing SQLite sessions from the defaultdistribution


> > 4) Marginally more secure then plain files
>
> Not at all.  :)  More files more better, you can have different
> permissions on each file, rather than the neive implementation of using
> one file for all sessions.  Sure you can use save_path per virtual host,
> but that's if you do it.  The default implementation is less secure, and
> that's what we have to count on.

Bullshit again.
You can have a session database per vhost and configure the permission of
that database per-vhost.



-- 
PHP Internals - PHP Runtime Development Mailing List
To unsubscribe, visit: http://www.php.net/unsub.php

Reply via email to