RE: [PHP] Authentication: is it a good solution?

From: Date: Wed, 27 Sep 2000 11:09:51 +0000
Subject: RE: [PHP] Authentication: is it a good solution?
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-17663@lists.php.net to get a copy of this message
> > What you've made, is somehow you're own session management, which > > PHP4 and a > > lot of other libraries already have implemented. > > Yes, infact I did so after I've read about sessions on php4 ... but just one > question: I know that PHPlib implements sessions... I'd like to know which > other libraries do so ... Try search on freshmeat.net (http://freshmeat.net/search/?q=session+php) > > Do you remove the unique ids from the db after a give time (Probably 15-20 > > minutes, after last access to site)? If not, this could result in a major > > security hole. > > Argh ... No, I don't remove it !!! Many thanks for your suggestion. Well, > I've planned yet to insert a logout function for the client, but how to do > it without the client logout action? I'm thinking about a usleep() function > to execute a logout code in addition with the ignore_user_abort() function > ..... Am I in the right way? Could be other solutions? You need some sort of garbage collecting function, which might could be invoked on each call to a secure page. Then the functions check when it last did some garbage collection etc. But the function has to be really optimized if it's going to be called on each script. Again, I would recommand that you use some of the already developed sessions management tools. If you doesn't like PHPLIB, you could try Prometheus API (http://prometheus.zerodivide.net/api/). There's no reason to develop the wheel more than once :) Regards, Lars Holm Nielsen <lars@hankat.dk>

« previous php.general (#17663) next »