RE: [PHP] DATABASE SESSION vs NON DB SESSION

From: Date: Sat, 14 Oct 2000 01:14:52 +0000
Subject: RE: [PHP] DATABASE SESSION vs NON DB SESSION
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-20112@lists.php.net to get a copy of this message
This is how I sort of do it. I pass the sid (random 16 character string, generated when the login and are authenticated properly) through URLs and hidden form elements. It checks to make sure they are still logged in and active. If they aren't active for 15 minutes, I have a cron'd php job that deletes their sid. If they come back after say, 16 minutes, and try to do something, they get a message saying they have to log in first. I use this method for about 2000 users and it works rather well. I'll be beefing up my sql and web servers though, to gain additional power though. =) marco -----Original Message----- From: Jason Cox [mailto:jasonc@webpipe.net] Sent: Friday, October 13, 2000 3:51 PM To: Todd Cary Cc: php-general@lists.php.net Subject: RE: [PHP] DATABASE SESSION vs NON DB SESSION The DB method can be slower than the server-side method especially under higher traffic conditions. For what you're doing, I would probably just use the native server-side sessions and let the SID propagate through query strings. Save yourself the trouble and possible headaches. Jason -----Original Message----- From: Todd Cary [mailto:todd@aristesoftware.com] Sent: Friday, October 13, 2000 4:24 PM To: jasonc@webpipe.net Cc: Jingle Balls; php-general@lists.php.net Subject: Re: [PHP] DATABASE SESSION vs NON DB SESSION I am very new to PHP and I am in the process of tracking sessions. Tentatively, I have chosen the DB route and I would like to clarify that I am on the correct track. When the surfer enters the Home page, I create a SessionID (time() ) and I put this into a hidden field. When the user goes to the next page, I again put the SessionID into a hidden field and I log the SessionID in the DB along with an Expire time. All subsequent pages create a hidden field containing the SessionID. Any information put in the database is linked to the SessionID. If I need to create a list of items belonging to the surfer, the table contains the SessionID and an expire time. To make the list "permanent" (e.g. confirms the order), I set the expire time to a high value (e.g. 1/1/2099). This seems to work...am I missing anything? Won't this work with multiple page server? I use a cookie as a "convenience" only. For instance, I will try to set a cookie with the SessionID so if the person returns at some other time, I can get the surfers name without needing to have the surfer enter some other value (e.g. phone number or e-mail address). Todd -- Todd Cary Ariste Software todd@aristesoftware.com -- PHP General Mailing List (http://www.php.net/) To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net For additional commands, e-mail: php-general-help@lists.php.net To contact the list administrators, e-mail: php-list-admin@lists.php.net _______________________________________________________ Site Design, Hosting, and E-Commerce at www.webpipe.net -- PHP General Mailing List (http://www.php.net/) To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net For additional commands, e-mail: php-general-help@lists.php.net To contact the list administrators, e-mail: php-list-admin@lists.php.net

« previous php.general (#20112) next »