'logged in' tracking...
| From: | Mark Peoples | Date: | Wed, 04 Oct 2000 18:18:44 +0000 |
| Subject: | 'logged in' tracking... | ||
| Groups: | php.general | ||
| Request: | Send a blank email to php-general+get-18637@lists.php.net to get a copy of this message | ||
Hi All,
Here's the problem.
A user logs in. When they click on a link to go to another page on the
site, we would like to keep their 'logged in' status alive. However, we
would like to do this without cookies, and, if possible, without the ?= in
the URL. Forms are possible, but buttons would look rather odd on some drop
menus we've put in there.
I looked at the session stuff for PHP4
(http://www.php.net/manual/ref.session.php), and, if I understand correctly,
if PHP is compiled with --enable-trans-sid , then the ?= in the URL is not
necessary. Is this correct? Would this solve our problem?
I have some session tracking scripts for PHP3, but they involved querying
the db every time a page loads, which although there would be minimal
effects for the user, is undesirable in this situation.
We have also considered using javascript, in which after a user logs in, we
created a 'hidden' frame with only their user-id and access status. In each
page with content, we would use js to grab those two variables from the
hidden frame and work from there.
We would prefer using what is available (the PHP4 sessions functionality).
Is that the way we should go or do you recommend another way?
Thanks,
Marco