RE: [PHP] DATABASE SESSION vs NON DB SESSION
| From: | Mark Peoples | Date: | Sat, 14 Oct 2000 01:14:52 +0000 |
| Subject: | RE: [PHP] DATABASE SESSION vs NON DB SESSION | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-20112@lists.php.net to get a copy of this message | ||
This is how I sort of do it.
I pass the sid (random 16 character string, generated when the login and are
authenticated properly) through URLs and hidden form elements. It checks to
make sure they are still logged in and active. If they aren't active for 15
minutes, I have a cron'd php job that deletes their sid. If they come back
after say, 16 minutes, and try to do something, they get a message saying
they have to log in first.
I use this method for about 2000 users and it works rather well. I'll be
beefing up my sql and web servers though, to gain additional power though.
=)
marco
-----Original Message-----
From: Jason Cox [mailto:jasonc@webpipe.net]
Sent: Friday, October 13, 2000 3:51 PM
To: Todd Cary
Cc: php-general@lists.php.net
Subject: RE: [PHP] DATABASE SESSION vs NON DB SESSION
The DB method can be slower than the server-side method especially under
higher traffic conditions. For what you're doing, I would probably just use
the native server-side sessions and let the SID propagate through query
strings. Save yourself the trouble and possible headaches.
Jason
-----Original Message-----
From: Todd Cary [mailto:todd@aristesoftware.com]
Sent: Friday, October 13, 2000 4:24 PM
To: jasonc@webpipe.net
Cc: Jingle Balls; php-general@lists.php.net
Subject: Re: [PHP] DATABASE SESSION vs NON DB SESSION
I am very new to PHP and I am in the process of tracking sessions.
Tentatively, I have chosen the DB route and I would like to clarify that
I am on the correct track.
When the surfer enters the Home page, I create a SessionID (time() ) and
I put this into a hidden field. When the user goes to the next page, I
again put the SessionID into a hidden field and I log the SessionID in
the DB along with an Expire time. All subsequent pages create a hidden
field containing the SessionID. Any information put in the database is
linked to the SessionID.
If I need to create a list of items belonging to the surfer, the table
contains the SessionID and an expire time. To make the list "permanent"
(e.g. confirms the order), I set the expire time to a high value (e.g.
1/1/2099).
This seems to work...am I missing anything? Won't this work with
multiple page server?
I use a cookie as a "convenience" only. For instance, I will try to set
a cookie with the SessionID so if the person returns at some other time,
I can get the surfers name without needing to have the surfer enter some
other value (e.g. phone number or e-mail address).
Todd
--
Todd Cary
Ariste Software
todd@aristesoftware.com
--
PHP General Mailing List (http://www.php.net/)
To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net
For additional commands, e-mail: php-general-help@lists.php.net
To contact the list administrators, e-mail: php-list-admin@lists.php.net
_______________________________________________________
Site Design, Hosting, and E-Commerce at www.webpipe.net
--
PHP General Mailing List (http://www.php.net/)
To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net
For additional commands, e-mail: php-general-help@lists.php.net
To contact the list administrators, e-mail: php-list-admin@lists.php.net