Re: Question regarding session-management with PHP3

From: Date: Tue, 12 Sep 2000 16:41:15 +0000
Subject: Re: Question regarding session-management with PHP3
References: 1  Groups: php.db 
Request: Send a blank email to php-db+get-2834@lists.php.net to get a copy of this message
There's no real magic to session handling... without PHP4's functions you can do it the old fashioned way. (In fact even with ASP in the past I've always done it this way because it gives you complete control over the whole scenario). When a user hits the site, use the following procedure: 1) Check for existence of a cookie that identifies the session (if you don't want to use cookies, then simuate them with a variable you pass from page to page that identifies the session - this is sort of a pain because you must include it on _every_ link in the site, but it works). 2) If cookie doesn't exist, generate a unique session ID and store it in a session table. For security, use a randomly generated string rather than an automatically incremented number. 3) If cookie does exist, look up the ID stored in the cookie in your session table. If it doesn't exist (e.g. you deleted old session data) go back to step 2. 4) Check system time against timestamp in session table to decide if it's expired or not 5) Update the session table with current timestamp. To simulate the session variables, either pass them from page to page within your forms/links or store whatever you want to in your session table. I don't know the details of how PHP stores session info internally so I don't know if this is more or less efficient that using the built in functions, though my gut would say more since you are using an SQL database designed for this sort of stuff instead of whatever method PHP uses (and I did see reference to the term "garbage collection" in the session docs which doesn't imply anything good ;-) Anyway, that's the basics. Just include code to do this at the top of every page before anything is output (or cookies won't work). For a password-protected site, you simply expand this a little bit... e.g. when a new session is created, give it an "access" level of 0. If your page is secured, when a user with access level 0 hits it, show a login form. Once they log in, update their session information with the correct access level. Jamie At 09:22 AM 9/12/00, Bart A. Verbeek wrote:
Hello, I'm wondering wether there is a way to use session-management in PHP3. I know PHP4 supports this (session-functions) but my Hosting-provider doesn't support PHP4 yet. Is it possible to copy the PHP4 functions and rewrite them for PHP3? Does anyone have Session-functions for PHP3? looking forward to a lot of answers.


« previous php.db (#2834) next »