Re: session confusion
| From: | php3 at developersdesk dot com | Date: | Fri, 23 Jun 2000 10:37:43 +0000 |
| Subject: | Re: session confusion | ||
| Groups: | php.general | ||
| Request: | Send a blank email to php-general+get-2764@lists.php.net to get a copy of this message | ||
Addressed to: "Michael Teter" <michael_teter@hotmail.com>
php-general@lists.php.net
** Reply to note from "Michael Teter" <michael_teter@hotmail.com> Fri, 23 Jun 2000
03:00:05 CDT
>
> 1. I have a simple login.php that starts a session, registers a flag
> "sessionActive", and then calls login2.php. login2.php checks to see
> whether "sessionActive" is registered. if so, it prints a positive
> message.
>
> in netscape (latest version with RH6.2), all is well at first. I
> click refresh and I get the same page (as I should.) I click refresh
> again and I get a netscape dialog box error "Netscape is unable to
> find the file or directory named /tmp/nsform3952D20E0B0082B. Check
> the name and try again." this same thing happens if I merely resize
> the window rather than click refresh twice. NOTE: I have no problems
> with my test scripts on IE5 or Mozilla.
>
I don't know about this, I've never seen it. I am using Netscape 4.61
on OS/2. One thing, php sessions set a bunch of headers to prevent
caching of the pages served under the session, this may have sonething
to do with it.
> 2. I understand that php sessions normally use cookies. what's the
> alternative?
PHP sessions attempt to use a cookie to propigate the session ID, if
that does not work it will add something like
?PHPSESSID=ieu8387432987543dsa08
to your url's. It does this behind the scenes, and usually works as
long as you send the entire url from a single print, echo, or outside
of the <? ?> tags.
The first time a session is started it does both an attempt to set a
cookie, and adds the session ID to all URLs created by the program. On
the next, and subsequent, pages it looks for a PHPSESSID cookie, and
adds the ID to the URL if one is not sent.
> I've thought about writing my own version of a session
> concept using database calls to store variables, but I don't know
> how to identify to whom they belong.
The PHP Base Library http://phplib.netuse.de contains
session code
you can use/study. There was no built in session code in PHP3, and
this library includes what is probably the most used PHP3 session code.
> I read that you can't go by IP
> because users from the same ISP may end up with same IP (I'm not
> sure I buy this...
I have no doubt about it. I have seen incidents in my log files where
a page request came in from one IP address at AOL, and a request for
an image on that page came in from a different address. I have also
seen what appears to be one person visiting the site come from more
than one IP address. It is not at all unusual, and AOL is not the only
one doing it.
I have also setup networks using NAT, where there are many web
browsers all sharing the same IP address. I have seen two or three
people simultaneiously running web browsers over these NAT connections.
They work just fine, and all share one Internet IP address.
There is also something called a proxy server that hides the details of
the network behind it, without using NAT. They will mess up IP based
session handling in the same way as NAT. (Many browsers, one IP
address.)
Don't even consider IP based sessions, they do not work...
> how would apache send a response?)
>
The individual connections are totally separate. A connection on the
Internet is identified by the IP address AND Port numbers on both ends
of the connection. The port number is different for the different
connections, even though the IP address is the same. Both NAT and
proxy servers juggle the IP address and port numbers of connections
passing through them.
> this is all blah blah, but basically I'm totally confused over a
> topic that seems like it should be simple (and based on the amount
> of coverage in the PHP4 docs, the developers must think it's pretty
> simple.)
Simplicity of a subject has nothing to do with it. Skimpy documentation
can be nothing more than a sign that a feature is new. Sessions were
added to PHP in version 4. They are quite new.
>
> hopefully someone can provide some direction for me (direct help or
> pointers to other information.)
You can find a number of good links to tutorials at:
http://www.php.net/links.php
and here:
http://www.developersdesk.com/web_site_help/phplinks.html
Weberdev, WebMonkey and DevShed come to mind as likely places to look
for good session informaton.
>
> my project is a "simple" web interface to a database. I want to have
> a login form that hits the database to validate the user (and
> determine what other actions that user is allowed to take.) then
> I'll have a few intelligent pages that will allow the user to do
> other database stuff (as long as I have state information so I know
> who is now attempting to do this other stuff.) etc. etc. I can
> clarify more if it will help.
That shouldn't be too hard. Spend an afternoon searching thru the
tutorials I have listed on that developersdesk.com page. I learned a
lot from them...
Rick Widmer
Internet Marketing Specialists
www.developersdesk.com