Re: Session management module - thoughts
| From: | Zeev Suraski | Date: | Sat, 29 May 1999 20:19:05 +0000 |
| Subject: | Re: Session management module - thoughts | ||
| References: | 1 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-6280@lists.php.net to get a copy of this message | ||
On Sat, 29 May 1999, David Fallon wrote:
> > I never was a member in the 'ASP sucks' club, and technology-wise, there's
> > a lot one can learn from Microsoft. The real question is 'since when is
> > every thing that Microsoft makes NOT good enough?'. I rarely find people
> > that actually blame Microsoft for what it has to be blamed; opensource
> > junkies usually just bash it for the hell of it. Fact is that the vast
> > majority of people will find ASP's session management framework to be all
> > they could possibly ask for in a session management system, and a 5 year
> > old can use it. Why add complexity and features where it's not necessary?
>
> There are two fundamental flaws to ASP's session management system. First,
> there's no support for querystring-based session management (as opposed to
> cookies). Second, there's no way of directly controlling the session
> management data. The RPC server described in earlier emails is amazingly
> useful for larger sites. It should probably be done in a second pass (as
> it's not necessary for the average joe, and would presumably require
> separate, more complicated setup). The hooks should be put in, though...
As long as the initial API is implemented first and doesn't suffer from
the complexity of the complex API, I'm ok with it. I don't think we
should care about it too much now.
> This is actually a fairly huge problem... There was that huge "scare" over
> cookies a few years back, and lots of people still have cookies turned off,
> either accidentally, or because they still believe that they could be giving
> out the personal bank account information using them. 40% might be a bit
> high, but it's not a totally unreasonable figure.
It looks totally unreasonable to me. And yes, I remember the scare, I was
working for an ISP back then and was working on relaxing people up.
Still, that was about 2 years ago. Two years ago my brother and sister
didn't have internet access, as well as most of my friends. They all have
it now, and I doubt any of them knows about these issues. They hardly
know what cookies are, let alone are scared of them. Since both major
browsers come with cookies turned on by default, I don't see how roughly
half of the people in the world could be running without cookies. I'd
imagine it's much closer to about 5%.
Zeev
--
-----------------------------------------------------
Zeev Suraski <zeev@zend.com>
For a PGP public key, finger bourbon@netvision.net.il
--
PHP Development Mailing List http://www.php.net/
To unsubscribe send an empty message to php-dev-unsubscribe@lists.php.net
For help: php-dev-help@lists.php.net