Re: cookie vs. database
| From: | Dean Hall | Date: | Mon, 21 Aug 2000 21:37:30 +0000 |
| Subject: | Re: cookie vs. database | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-12816@lists.php.net to get a copy of this message | ||
On Mon, 21 Aug 2000, Xiaoli Hu wrote:
> Hi,
>
> In a typical E-commerce application, e.g. an online bookstore, I have all
> books listed and a button "Add to cart" next to it so user can just click on
> that to buy it. Question is: I found on a book the authors use cookies to
> store those information related to books clicked by user, instead of
> inserting them to the backend database table "transaction"(although it is
> created and already there). Is there any reason we need to do it this way,
> or just 2 options? I am thinking it might have sth. to do with the stateless
> feature of HTTP request, but still can't see exactly why.
Well, the stateless feature of HTTP is why you'd want to store the user's
transaction data by some means, yes. If you store it in a database or in a
cookie, you need some way to assure that the data is unique to one user,
and that it hasn't been spoofed. That's the advantage of PHP sessions. PHP
sessions can use cookies or GET variables or a database or even shared
memory on the server to store session data. If you use PHP sessions with
anything other than cookies or GET variables (e.g., with a database),
you'll have to set your session handler.
In any case PHP sessions basically assures you that you're always talking
to the same user by the session ID which is cryptographically unique. Of
course the session_start() function takes care of getting all the user's
data for you.
And be sure not to use a one-click ordering feature. Send users to a
confirmation page when they order so you won't violate Amazon.com's
so-called patent.
>
> Any help is most appreciated.
>
>
> hxl
> ________________________________________________________________________
> Get Your Private, Free E-mail from MSN Hotmail at
> http://www.hotmail.com
>
>
>