Re: Sessions proposal
| From: | Andr� N�ss | Date: | Fri, 30 Nov 2001 15:32:04 +0000 |
| Subject: | Re: Sessions proposal | ||
| References: | 1 2 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-72144@lists.php.net to get a copy of this message | ||
"John Lim" <heyjohnlim@yahoo.com> wrote in message
news:20011130152442.30382.qmail@pb1.pair.com...
> Hi Andre
>
> Why not simply store the login time as a session variable, and log the
> person
> out after 15 mins?
>
> Regards, John
Maybe I was unclear. The problem is that to allow for 2 hour timeouts I need
to have gc_maxlifetime set to 2 hours, but for 99,9% of all session I don't
need than 15 minutes gc_maxlifetime since they have a cookie lifetime of 15
minutes.
Also, I can't log the user out after 15 minutes (it's better to use
cookie_lifetime for that), I haven't got any idea of where he is, so storing
the login time as a session variable won't let me change the gc_maxlifetime.
André Næss
>
> André NæSs <andrena@ifi.uio.no> wrote in message
> news:20011130151322.21026.qmail@pb1.pair.com...
> > I find PHP session lacking in one area. In my applications I typically
> want
> > to have a long timeout for adminstrators so that they don't have to log
in
> > all the time. A typical value is 2 hours. For users I prefer 15 minutes,
> > based on the assumption that a user will go in, do his stuff, and leave.
> For
> > this to happen I need to have the gc_maxlifetime set to 2 hours, or risk
> > unpredictable results for the administrators. The problem with this is
of
> > course that garbage collection will run infrequently for the entire
> system,
> > even though most of the sessions expire after 15 minutes. It would
> therefore
> > be nice to have something like "session contexts", where you could have
> > different session settings for each context. Is this possible to
achieve?
> > Anyone else who can see the use of this?
> >
> > Regards.
> > André Næss
> >
> >
>
>