Re: Session management module - thoughts
| From: | David Fallon | Date: | Sat, 29 May 1999 20:06:38 +0000 |
| Subject: | Re: Session management module - thoughts | ||
| References: | 1 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-6279@lists.php.net to get a copy of this message | ||
> I never was a member in the 'ASP sucks' club, and technology-wise, there's
> a lot one can learn from Microsoft. The real question is 'since when is
> every thing that Microsoft makes NOT good enough?'. I rarely find people
> that actually blame Microsoft for what it has to be blamed; opensource
> junkies usually just bash it for the hell of it. Fact is that the vast
> majority of people will find ASP's session management framework to be all
> they could possibly ask for in a session management system, and a 5 year
> old can use it. Why add complexity and features where it's not necessary?
There are two fundamental flaws to ASP's session management system. First,
there's no support for querystring-based session management (as opposed to
cookies). Second, there's no way of directly controlling the session
management data. The RPC server described in earlier emails is amazingly
useful for larger sites. It should probably be done in a second pass (as
it's not necessary for the average joe, and would presumably require
separate, more complicated setup). The hooks should be put in, though...
> > In addition to cookie base session tracking, ASP also supports URL
> > based session IDs, I think this is also crucial as it has been reported
> > that as much as 40% of the users out there have cookies turned off.
>
> Where's that 40% figure from? I'd imagine it's totally bogus. Again,
> considering Microsoft requires cookies enabled for well over half of its
> web site, I truly doubt they intentionally give up 40% of their users.
> You can say whatever you want about Microsoft, but they're not keen on
> losing users.
This is actually a fairly huge problem... There was that huge "scare" over
cookies a few years back, and lots of people still have cookies turned off,
either accidentally, or because they still believe that they could be giving
out the personal bank account information using them. 40% might be a bit
high, but it's not a totally unreasonable figure.
--
PHP Development Mailing List http://www.php.net/
To unsubscribe send an empty message to php-dev-unsubscribe@lists.php.net
For help: php-dev-help@lists.php.net