R: [PHP] Authentication: is it a good solution?
| From: | n e t b r a i n | Date: | Wed, 27 Sep 2000 16:44:12 +0000 |
| Subject: | R: [PHP] Authentication: is it a good solution? | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-17724@lists.php.net to get a copy of this message | ||
Lars wrote:
> What you've made, is somehow you're own session management, which
> PHP4 and a
> lot of other libraries already have implemented.
Yes, infact I did so after I've read about sessions on php4 ... but just one
question: I know that PHPlib implements sessions... I'd like to know which
other libraries do so ...
> Do you remove the unique ids from the db after a give time (Probably 15-20
> minutes, after last access to site)? If not, this could result in a major
> security hole.
Argh ... No, I don't remove it !!! Many thanks for your suggestion. Well,
I've planned yet to insert a logout function for the client, but how to do
it without the client logout action? I'm thinking about a usleep() function
to execute a logout code in addition with the ignore_user_abort() function
..... Am I in the right way? Could be other solutions?
Really, many thanks for your help.
max