I still don't get it. The browser gets the session cookie even though the request processing crashed? Or does another request manage to pick up the session that was dropped from the crashed request?
I don't do PHP. It just sounds incredible to me that so little isolation seems to exist.
I don't do PHP. It just sounds incredible to me that so little isolation seems to exist.