To avoid storing session data on the server, you can sign the content that you want to protect from changes before saving the session, and then check immediately after retrieving from the session. In PHP, this process is reasonably simple and fixes server problems.
Please note that this does not protect session data from rendering. If you need this protection, you can still avoid storing on the server using secure encryption. Just be careful that virtually every encryption scheme based on the size of the key can be broken in the near future. Therefore, if you need to protect session data for, say, 5 years, the safe choice of key and algorithm can create performance problems.
fernacolo
source share