From: Tom Danielsen Date: 2003-05-31T08:57:58+09:00 Subject: Re: [Q]: CGI::Session On 31.05 00:52, ahoward wrote: | On Sat, 31 May 2003, Yukihiro Matsumoto wrote: | | > Hi, | > | > In message "[Q]: CGI::Session" | > on 03/05/29, Tom Danielsen writes: | > | > |- why is only the first part of the MD5 sum used in | > | the session_id ? | > | > Not to make file names too long (Perl's CGI session does this too). I | > believe it is secure enough. Ok, I see this point. However - for me performance is not an issue, it would be nice if this behaviour was configurable. For my use this is just an unneccesary reduction of security (even if security still is good). | > | > |- why does CGI::Session::FileStore write the session | > | variables as text, instead of using Marshal ? | > | > Allow users to choose their own stringify method. | > | > matz. | | matz- | | if it were cleaned up a bit, what would you think about including my (or a | better impl) of CGI::Session::Pstore in the standard lib? | | i use it all the time for cgi scripts and have found it to be really useful. | I do agree, this would be nice to have in the standard distribution. CGI::Session::Pstore works great! Now if i could just figure out what went wrong with my code.... :-) Tom