Re: Session management module - thoughts
| From: | Zeev Suraski | Date: | Fri, 28 May 1999 15:28:51 +0000 |
| Subject: | Re: Session management module - thoughts | ||
| References: | 1 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-6167@lists.php.net to get a copy of this message | ||
On Fri, 28 May 1999, Rasmus Lerdorf wrote:
> It's one of those marketing checkmark features that I do agree are
> important. Basically if you are writing a database-driven site, tossing
> in a cookie and storing user data alongside your other data is pretty
> simple. But for Joe User out there, having a simple session mechanism
> would be a good idea.
It's actually beyond marketing. As someone that doesn't like messing with
PHP scripts too much, I haven't yet installed phplib, and thus, never used
sessions. I'm sure there are many other people in the same situation...
> Why do we need to lock? Assuming each session gets its own unique file
> there should theoretically never be more than one process reading/writing
> that file. Do you mean to make sure the session cleaning thing doesn't
> clean an active session? We could just check stat.m_time on the file or
> something.
Hmm, that's not true; Your browser opens many HTTP connections to the
same web server with the same cookie - it may blow up.
> The locking worries me a little bit because a lot of big sites have their
> web pages on NFS-mounted partitions and the lockd/statd locking for NFS is
> crappy. If we do need to lock, we might want to make sure we have some
> way to define a session_directory in php3.ini and add a little hint
> telling people to point this at a non-NFS location.
We definitely need a session directory.
Zeev
--
-----------------------------------------------------
Zeev Suraski <zeev@zend.com>
For a PGP public key, finger bourbon@netvision.net.il
--
PHP Development Mailing List http://www.php.net/
To unsubscribe send an empty message to php-dev-unsubscribe@lists.php.net
For help: php-dev-help@lists.php.net