Re: Session management module - thoughts

From: Date: Sat, 29 May 1999 20:06:38 +0000
Subject: Re: Session management module - thoughts
References: 1  Groups: php.dev 
Request: Send a blank email to php-dev+get-6279@lists.php.net to get a copy of this message
> I never was a member in the 'ASP sucks' club, and technology-wise, there's > a lot one can learn from Microsoft. The real question is 'since when is > every thing that Microsoft makes NOT good enough?'. I rarely find people > that actually blame Microsoft for what it has to be blamed; opensource > junkies usually just bash it for the hell of it. Fact is that the vast > majority of people will find ASP's session management framework to be all > they could possibly ask for in a session management system, and a 5 year > old can use it. Why add complexity and features where it's not necessary? There are two fundamental flaws to ASP's session management system. First, there's no support for querystring-based session management (as opposed to cookies). Second, there's no way of directly controlling the session management data. The RPC server described in earlier emails is amazingly useful for larger sites. It should probably be done in a second pass (as it's not necessary for the average joe, and would presumably require separate, more complicated setup). The hooks should be put in, though... > > In addition to cookie base session tracking, ASP also supports URL > > based session IDs, I think this is also crucial as it has been reported > > that as much as 40% of the users out there have cookies turned off. > > Where's that 40% figure from? I'd imagine it's totally bogus. Again, > considering Microsoft requires cookies enabled for well over half of its > web site, I truly doubt they intentionally give up 40% of their users. > You can say whatever you want about Microsoft, but they're not keen on > losing users. This is actually a fairly huge problem... There was that huge "scare" over cookies a few years back, and lots of people still have cookies turned off, either accidentally, or because they still believe that they could be giving out the personal bank account information using them. 40% might be a bit high, but it's not a totally unreasonable figure. -- PHP Development Mailing List http://www.php.net/ To unsubscribe send an empty message to php-dev-unsubscribe@lists.php.net For help: php-dev-help@lists.php.net

« previous php.dev (#6279) next »