Re: Session management module - thoughts
| From: | Jim Winstead | Date: | Fri, 28 May 1999 16:54:41 +0000 |
| Subject: | Re: Session management module - thoughts | ||
| References: | 1 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-6175@lists.php.net to get a copy of this message | ||
On May 28, Zeev Suraski wrote:
> What I have in mind is a KISS approach to sessions, through a built-in PHP
> module. For information storage - use files. Implement functions that
> start a session, that add variables to a session, and possibly that end a
> session. At request_shutdown, simply store all variables that were
> registered as session varaibles in a file, named after a unique key that's
> generated by the session starter, and passed along through cookies (I
> think it'll be fair to rely on cookies, and point people that don't trust
> cookies to phplib's session support).
The whole mechanism should also allow hooks for user-defined
retrieval and storage functions, so alternate methods of storing
the data can be implemented easily. That will be nice for prototyping,
as well.
One problem is keeping track of the session key, though. Relying on
cookies is only okay if you're willing to let people slip through
the cracks. Otherwise you have to do URL munging and slipping the
session id in as hidden form data on forms. How does PHPLIB deal
with this?
Jim
--
PHP Development Mailing List http://www.php.net/
To unsubscribe send an empty message to php-dev-unsubscribe@lists.php.net
For help: php-dev-help@lists.php.net