Re: Sessions proposal

From: Date: Fri, 30 Nov 2001 15:32:04 +0000
Subject: Re: Sessions proposal
References: 1 2  Groups: php.dev 
Request: Send a blank email to php-dev+get-72144@lists.php.net to get a copy of this message
"John Lim" <heyjohnlim@yahoo.com> wrote in message news:20011130152442.30382.qmail@pb1.pair.com... > Hi Andre > > Why not simply store the login time as a session variable, and log the > person > out after 15 mins? > > Regards, John Maybe I was unclear. The problem is that to allow for 2 hour timeouts I need to have gc_maxlifetime set to 2 hours, but for 99,9% of all session I don't need than 15 minutes gc_maxlifetime since they have a cookie lifetime of 15 minutes. Also, I can't log the user out after 15 minutes (it's better to use cookie_lifetime for that), I haven't got any idea of where he is, so storing the login time as a session variable won't let me change the gc_maxlifetime. André Næss > > André NæSs <andrena@ifi.uio.no> wrote in message > news:20011130151322.21026.qmail@pb1.pair.com... > > I find PHP session lacking in one area. In my applications I typically > want > > to have a long timeout for adminstrators so that they don't have to log in > > all the time. A typical value is 2 hours. For users I prefer 15 minutes, > > based on the assumption that a user will go in, do his stuff, and leave. > For > > this to happen I need to have the gc_maxlifetime set to 2 hours, or risk > > unpredictable results for the administrators. The problem with this is of > > course that garbage collection will run infrequently for the entire > system, > > even though most of the sessions expire after 15 minutes. It would > therefore > > be nice to have something like "session contexts", where you could have > > different session settings for each context. Is this possible to achieve? > > Anyone else who can see the use of this? > > > > Regards. > > André Næss > > > > > >

« previous php.dev (#72144) next »