Re: Session management module - thoughts

From: Date: Sat, 29 May 1999 10:19:19 +0000
Subject: Re: Session management module - thoughts
References: 1  Groups: php.dev 
Request: Send a blank email to php-dev+get-6233@lists.php.net to get a copy of this message
On Fri, 28 May 1999, Jim Winstead wrote: > We can't tell ISPs what do do. We're not really talking about moving > files around, just allowing the user to say "put my PHP session > data in this directory/file". This doesn't require any more goodwill > on the ISPs side than letting their users fopen() a file and write > to it does now. Getting them to configure a location for user's > session data does. I really think that we can tell ISPs what to do. We deliver an application, they need to configure it if they want it to work right. If they don't care about it working right, their users would switch to another ISP. I don't think we should do the wrong thing because some ISPs are dumb or lazy. Just 'letting their users fopen() a file and write to it' is a huge security hole, even if you made it sound innocent. > That's assuming that the ISP is running PHP as a module, and there > are some large ones which do not, but which support PHP as CGI > (which is absolutely reasonable and perfectly justifiable, and > unlikely to change). And the policy I speak of doesn't make its > distinction based on the userid running the process. If my website > starts a process, it's still my process. :) > > We just need to support that case in addition to anything fancy. > Doing it per-request (or per-Nth-request to minimize the performance > impact) is just a fallback position. In fact, the per-Nth-request > could probably be optimized to the-first-time-a-session-is-run-per-day > using a file with its timestamp indicating the last time the cleanup > was run. > > However, we should definitely provide a standalone "cleaner" that > people with reasonable intelligence and control over their situation > can simply run nightly (or however often they desire) via cron. > This is undoubtedly the optimal configuration, but difficult to > have automatically configured out of the box. We can probably support a standalone cleaner. In that case, it would be more than fair to require the ISP to put that cleaner in a crontab or next to the httpd startup. Again, I don't think we should aim at doing something that requires zero configuration and works slowly if we can do something that requires 5 minutes of configuration and works efficiently. Zeev -- ----------------------------------------------------- Zeev Suraski <zeev@zend.com> For a PGP public key, finger bourbon@netvision.net.il -- PHP Development Mailing List http://www.php.net/ To unsubscribe send an empty message to php-dev-unsubscribe@lists.php.net For help: php-dev-help@lists.php.net

« previous php.dev (#6233) next »