- global $base_uri;
-
- if ( (float)substr(PHP_VERSION , 0 , 3) < 4.1) {
- global $HTTP_SESSION_VARS;
- $HTTP_SESSION_VARS = array();
- }
- else {
- $_SESSION = array();
- }
-
- /*
- * now reset cookies to 5 seconds ago to delete from browser
- */
-
- @session_destroy();
- $cookie_params = session_get_cookie_params();
- setcookie(session_name(), '', time() - 5, $cookie_params['path'],
- $cookie_params['domain']);
- setcookie('username', '', time() - 5, $base_uri);
- setcookie('key', '', time() - 5 , $base_uri);
-
+
+ /*
+ * php.net says we can kill the cookie by setting just the name:
+ * http://www.php.net/manual/en/function.setcookie.php
+ * maybe this will help fix the session merging again.
+ *
+ * Changed the theory on this to kill the cookies first starting
+ * a new session will provide a new session for all instances of
+ * the browser, we don't want that, as that is what is causing the
+ * merging of sessions.
+ */
+
+ global $base_uri;
+
+ if (isset($_COOKIE[session_name()])) setcookie(session_name(), '', time() - 5, $base_uri);
+ if (isset($_COOKIE['username'])) setcookie('username','',time() - 5,$base_uri);
+ if (isset($_COOKIE['key'])) setcookie('key','',time() - 5,$base_uri);
+
+ $sessid = session_id();
+ if (!empty( $sessid )) {
+ if ( !check_php_version(4,1) ) {
+ global $HTTP_SESSION_VARS;
+ $HTTP_SESSION_VARS = array();
+ } else {
+ $_SESSION = array();
+ }
+ @session_destroy();
+ }
+
+}
+
+/*
+ * Function to verify a session has been started. If it hasn't
+ * start a session up. php.net doesn't tell you that $_SESSION
+ * (even though autoglobal), is not created unless a session is
+ * started, unlike $_POST, $_GET and such
+ */
+
+function sqsession_is_active() {
+
+ $sessid = session_id();
+ if ( empty( $sessid ) ) {
+ session_start();
+ }