RE: [PHP] How to handle "so called" expired sessions??

From: Date: Tue, 03 Dec 2002 18:01:07 +0000
Subject: RE: [PHP] How to handle "so called" expired sessions??
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-126889@lists.php.net to get a copy of this message
> Ive just been getting myself deep into using sessions. > Sessions are working as it should except for one condition. > Say I log into the site, and the session is started, and I don't do > anything for the next 30 mins, then go back to the site. > Im temporarily logged out, but because the session cookie is still good, > the next page load logs me back in. > How do the people who use sessions handle this type of scenario?? Whether your logged back in or not is dependant on your program. Once you are gone for over X minutes, your session file is deleted. So, even though the cookie is still good, the session will not have any data. What's usually done is to check for a certain session value, like $_SESSION['logged_in'] and if it's present, then continue, otherwise force the user to log back in again. ---John Holmes...

« previous php.general (#126889) next »