Re: Session management.
| From: | Mukul Sabharwal | Date: | Mon, 22 May 2000 05:17:03 +0000 |
| Subject: | Re: Session management. | ||
| Groups: | php.general | ||
| Request: | Send a blank email to php-general+get-267@lists.php.net to get a copy of this message | ||
Hi,
> I want to know how to check if a session is already
> active. I need this check
> in order to prevent unauthorised access.
Well try this code, i use it :
http://www.nexen.net/phparena/
session_start(); // get all the stuff
if(time() > ($time + 3600)) // check if inactive for
an hour
{ // if yes then blow the session and print the stuff
session_destroy(); // blow
echo "You need to <a href=login.php>re-login</a>";
exit;
}
and here you can have the code...
> Another thing is that when I call the
> session_destroy() to end my session, php
> will destroy the session from the server, ie remove
> the session file but it
> will not destroy the cookie. I tried to destroy the
> cookie manually by calling
> setcookie("PHPSESSID", 0) but this just doesnt work.
> I tried to give it the
> correct domain names and path but still it does not
> work. The old value of cookie
> is still kept. I want destroy the cookie so that
> when the user logs in again
> before the cookie times out, they will get a new
> session id.
You don't need to do this... the session id is now
rotten.. and can't be used... though i'm not sure..
Bye! Hope this helps
=====
FreeStuff Online
PHP Arena
MP3 Meta Search
Mukul[ICQ# : 36002412]
__________________________________________________
Do You Yahoo!?
Send instant messages & get email alerts with Yahoo! Messenger.
http://im.yahoo.com/