RE: [PHP] Deleting session vars
| From: | Jeroen Wesbeek | Date: | Tue, 31 Oct 2000 14:44:15 +0000 |
| Subject: | RE: [PHP] Deleting session vars | ||
| Groups: | php.general | ||
| Request: | Send a blank email to php-general+get-22942@lists.php.net to get a copy of this message | ||
Only the session variable is stored in the cookie and the
environment you have registered in the session is stored
on the server in the session file. So there is totally no
database interaction needed for a session since the php4
session system organizes it all...
Need I say more? Then read http://www.php.net/manual/html/ref.session.html
Grtz,
dowebwedo
Jeroen Wesbeek
.programming
St. Jacobsstraat 16
Postbus 448 | 3500 AK Utrecht
The Netherlands
p 030 2348110 | f 030 2348605
[roses are red, violets are blue,
I am schizophrenic and so am I ]
-----Original Message-----
From: Maxim Maletsky [mailto:maxim.maletsky@japaninc.net]
Sent: dinsdag 31 oktober 2000 12:33
To: 'Boris Crismancich'
Cc: 'PHP General List. (E-mail)'
Subject: RE: [PHP] Deleting session vars
wait a minute, sessions are using cookies, it's authenticating the UNIQUE
SID registered in my browser,
so at the same time Maxim and Boris can browse the same area.
Your server simply checks for my cookie (if session started), gets the SID
and pulls the data out from Hard Drive.
If you register something into the database you need then UPDATE staff SET
whatever=whatever WHERE SID=$SID, so in this case we do not overwrite each
other.
right?
tell me I am wrong...
I think I just misunderstood your question ..
-----Original Message-----
From: Boris Crismancich [mailto:crismancich@wettermacher.de]
Sent: Tuesday, October 31, 2000 8:24 PM
To: Maxim Maletsky
Subject: Re: [PHP] Deleting session vars
Imagine youre on a page and youre member... you log in with your name and
your password.
name="name" value="Maxim"
name="password" value="dunno"
are submitted to the PHP script.
_____________________________
script:
Session Var "userid" is registered.
If name and pasword are correct,
userid is set to name: $userid = $name;
______________________________
Now youre surfing through the Site saving sth to your Profile.
Now your friend wants to enter his Profile (Same computer, sessions still
registered)
and loggs in with following Form data:
name="name" value="Boris"
name="password" value="askme"
Now the same Login Script registers "userid"
and now should look wether askme is the right
password for Boris, but sadly $name still contains
Maxim. So there seems to be sth like a reference between
$name and $userid, but I have not set it.
When I leave out Session_start(), anything works ok.
But then I cant register Boris as new User ID.