For logging purposes I have to store the client PHPSESSID onto database.
Assuming that the session are expired, are there any bad practises linked to this? Can someone predict a PHPSESSID by reading the list?
Grateful to hear any situation where this can lead to a security problem.