Re: Session management module - thoughts
| From: | Zeev Suraski | Date: | Sat, 29 May 1999 10:19:19 +0000 |
| Subject: | Re: Session management module - thoughts | ||
| References: | 1 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-6233@lists.php.net to get a copy of this message | ||
On Fri, 28 May 1999, Jim Winstead wrote:
> We can't tell ISPs what do do. We're not really talking about moving
> files around, just allowing the user to say "put my PHP session
> data in this directory/file". This doesn't require any more goodwill
> on the ISPs side than letting their users fopen() a file and write
> to it does now. Getting them to configure a location for user's
> session data does.
I really think that we can tell ISPs what to do. We deliver an
application, they need to configure it if they want it to work right. If
they don't care about it working right, their users would switch to
another ISP. I don't think we should do the wrong thing because some ISPs
are dumb or lazy.
Just 'letting their users fopen() a file and write to it' is a huge
security hole, even if you made it sound innocent.
> That's assuming that the ISP is running PHP as a module, and there
> are some large ones which do not, but which support PHP as CGI
> (which is absolutely reasonable and perfectly justifiable, and
> unlikely to change). And the policy I speak of doesn't make its
> distinction based on the userid running the process. If my website
> starts a process, it's still my process. :)
>
> We just need to support that case in addition to anything fancy.
> Doing it per-request (or per-Nth-request to minimize the performance
> impact) is just a fallback position. In fact, the per-Nth-request
> could probably be optimized to the-first-time-a-session-is-run-per-day
> using a file with its timestamp indicating the last time the cleanup
> was run.
>
> However, we should definitely provide a standalone "cleaner" that
> people with reasonable intelligence and control over their situation
> can simply run nightly (or however often they desire) via cron.
> This is undoubtedly the optimal configuration, but difficult to
> have automatically configured out of the box.
We can probably support a standalone cleaner. In that case, it would be
more than fair to require the ISP to put that cleaner in a crontab or next
to the httpd startup.
Again, I don't think we should aim at doing something that requires zero
configuration and works slowly if we can do something that requires 5
minutes of configuration and works efficiently.
Zeev
--
-----------------------------------------------------
Zeev Suraski <zeev@zend.com>
For a PGP public key, finger bourbon@netvision.net.il
--
PHP Development Mailing List http://www.php.net/
To unsubscribe send an empty message to php-dev-unsubscribe@lists.php.net
For help: php-dev-help@lists.php.net