会话数据如何在页面间传递?PHP表单提交会话传值疑问
Great question! Let's break down exactly how your submitted name travels from index.php to page.php using PHP sessions—no magic, just straightforward server-client communication.
Core Idea of PHP Sessions
PHP sessions work by tying user-specific data to a unique Session ID (a long random string). This ID is the only thing sent back and forth between the browser and server; the actual session data (like your name value) lives on the server (usually in temporary files, though you can configure it to use databases or other storage).
Step-by-Step Breakdown of Your Example
Starting the Session in
index.php
You might have omitted it in your snippet, but to use$_SESSION, you must first callsession_start()at the very top ofindex.php(before any HTML output). When this runs for the first time:- PHP generates a unique Session ID (e.g.,
abc123xyz). - It sends a
Set-Cookieheader to the browser, storing the ID in a cookie namedPHPSESSIDby default. - It creates a temporary file on the server to store session data for this ID.
Here's the complete, functional
index.php:<?php session_start(); // Critical: must come before any output if ($_SERVER['REQUEST_METHOD'] === 'POST') { // Store the submitted name in the session $_SESSION['name'] = $_POST['name']; // Redirect to page.php header('Location: page.php'); exit; // Always exit after a header redirect to stop further code execution } ?> <form method="post"> <input type="text" name="name" placeholder="Enter your name"> <button type="submit">Sign Up</button> </form>- PHP generates a unique Session ID (e.g.,
Storing the Name and Redirecting
When the user submits the form,$_POST['name']captures their input. Assigning this to$_SESSION['name']writes the value to the server's temporary session file tied to their Session ID. Theheader('Location: page.php')tells the browser to request the new page.Retrieving the Data in
page.php
When the browser requestspage.php, it automatically sends thePHPSESSIDcookie back to the server. When you callsession_start()here:- PHP reads the Session ID from the cookie.
- It looks up the corresponding session file on the server.
- It loads all stored data (including
name) into the$_SESSIONsuperglobal.
Your
page.phpshould include a security best practice to prevent XSS attacks:<?php session_start(); ?> <h3>Thank you <?php echo htmlspecialchars($_SESSION['name']);?>, for signing up.</h3>
Edge Case Note
If a user has cookies disabled, PHP can fall back to URL rewriting (appending the Session ID to the URL like page.php?PHPSESSID=abc123xyz), but this is less secure and not enabled by default. Most modern browsers allow cookies, so the default method works for almost all users.
Key Takeaways
- Session data is stored server-side—only the Session ID is sent to the browser.
- The Session ID is passed between pages via a cookie (default) or URL.
session_start()is mandatory on every page that needs access to session data—it handles loading the correct user's data.
内容的提问来源于stack exchange,提问作者Garrett Rose

