Re: Session management module - thoughts

From: Date: Fri, 28 May 1999 17:35:23 +0000
Subject: Re: Session management module - thoughts
References: 1 2 3 4  Groups: php.dev 
Request: Send a blank email to php-dev+get-6186@lists.php.net to get a copy of this message
On Fri, May 28, 1999 at 10:17:31AM -0700, Phil Glatz wrote: > At 09:54 AM 5/28/99 , Jim Winstead wrote: > >One problem is keeping track of the session key, though. Relying on > >cookies is only okay if you're willing to let people slip through > >the cracks. > > More than that, in the "real world", lots of people don't accept cookies > for various reason (older browsers, paranoia). > > I'm working on a very large ecommerce site. One of our directives to reach > a maximum office is to allow cookies and javascript as a convenience, but > do not require their use for the site to work. As much as I like them, we > cannot assume all users will have them enabled. Up to here, I can sign every word. The "get" mode (where you embed the session id in the url and don't use cookies) has security and speed impacts. First, the session id may be exposed to remote sites through the "Referer" HTTP header. This allows a malicious administrator to exploit all services connected with the session id. Second, changing all URLs in a document is very inefficient. You cannot cache pages, but have to regenerate each single one. This also makes it nearly impossible to design a site using a normal HTML design tool, because "normal" designers are not clever enough to use PHP code correctly. Telling users to turn on cookies is not a solution for everyone. One part is too silly to dig up the configure option and the other half has learned "everything" about the danger of cookies in the latest "Computer BILD" (could you say "trolls"). > I like the use of authentication, but there is no way currently to do this > on our site (at least until a mod_auth_oracle comes along). > > I'm of the opinion that session management is probably best implemented > outside core PHP, possibly as a series of class libraries. I don't see how > one general implementation will be usable by all. You can use PHPLIB, of course. The people working on it have spent months on producing this very fine set of classes. I don't think we are going to duplicate all of its functionality in PHP4. -- Regards, Sascha Schumann Consultant -- PHP Development Mailing List http://www.php.net/ To unsubscribe send an empty message to php-dev-unsubscribe@lists.php.net For help: php-dev-help@lists.php.net

« previous php.dev (#6186) next »