Re: session confusion

From: Date: Fri, 23 Jun 2000 10:37:43 +0000
Subject: Re: session confusion
Groups: php.general 
Request: Send a blank email to php-general+get-2764@lists.php.net to get a copy of this message
Addressed to: "Michael Teter" <michael_teter@hotmail.com> php-general@lists.php.net ** Reply to note from "Michael Teter" <michael_teter@hotmail.com> Fri, 23 Jun 2000 03:00:05 CDT > > 1. I have a simple login.php that starts a session, registers a flag > "sessionActive", and then calls login2.php. login2.php checks to see > whether "sessionActive" is registered. if so, it prints a positive > message. > > in netscape (latest version with RH6.2), all is well at first. I > click refresh and I get the same page (as I should.) I click refresh > again and I get a netscape dialog box error "Netscape is unable to > find the file or directory named /tmp/nsform3952D20E0B0082B. Check > the name and try again." this same thing happens if I merely resize > the window rather than click refresh twice. NOTE: I have no problems > with my test scripts on IE5 or Mozilla. > I don't know about this, I've never seen it. I am using Netscape 4.61 on OS/2. One thing, php sessions set a bunch of headers to prevent caching of the pages served under the session, this may have sonething to do with it. > 2. I understand that php sessions normally use cookies. what's the > alternative? PHP sessions attempt to use a cookie to propigate the session ID, if that does not work it will add something like ?PHPSESSID=ieu8387432987543dsa08 to your url's. It does this behind the scenes, and usually works as long as you send the entire url from a single print, echo, or outside of the <? ?> tags. The first time a session is started it does both an attempt to set a cookie, and adds the session ID to all URLs created by the program. On the next, and subsequent, pages it looks for a PHPSESSID cookie, and adds the ID to the URL if one is not sent. > I've thought about writing my own version of a session > concept using database calls to store variables, but I don't know > how to identify to whom they belong. The PHP Base Library http://phplib.netuse.de contains session code you can use/study. There was no built in session code in PHP3, and this library includes what is probably the most used PHP3 session code. > I read that you can't go by IP > because users from the same ISP may end up with same IP (I'm not > sure I buy this... I have no doubt about it. I have seen incidents in my log files where a page request came in from one IP address at AOL, and a request for an image on that page came in from a different address. I have also seen what appears to be one person visiting the site come from more than one IP address. It is not at all unusual, and AOL is not the only one doing it. I have also setup networks using NAT, where there are many web browsers all sharing the same IP address. I have seen two or three people simultaneiously running web browsers over these NAT connections. They work just fine, and all share one Internet IP address. There is also something called a proxy server that hides the details of the network behind it, without using NAT. They will mess up IP based session handling in the same way as NAT. (Many browsers, one IP address.) Don't even consider IP based sessions, they do not work... > how would apache send a response?) > The individual connections are totally separate. A connection on the Internet is identified by the IP address AND Port numbers on both ends of the connection. The port number is different for the different connections, even though the IP address is the same. Both NAT and proxy servers juggle the IP address and port numbers of connections passing through them. > this is all blah blah, but basically I'm totally confused over a > topic that seems like it should be simple (and based on the amount > of coverage in the PHP4 docs, the developers must think it's pretty > simple.) Simplicity of a subject has nothing to do with it. Skimpy documentation can be nothing more than a sign that a feature is new. Sessions were added to PHP in version 4. They are quite new. > > hopefully someone can provide some direction for me (direct help or > pointers to other information.) You can find a number of good links to tutorials at: http://www.php.net/links.php and here: http://www.developersdesk.com/web_site_help/phplinks.html Weberdev, WebMonkey and DevShed come to mind as likely places to look for good session informaton. > > my project is a "simple" web interface to a database. I want to have > a login form that hits the database to validate the user (and > determine what other actions that user is allowed to take.) then > I'll have a few intelligent pages that will allow the user to do > other database stuff (as long as I have state information so I know > who is now attempting to do this other stuff.) etc. etc. I can > clarify more if it will help. That shouldn't be too hard. Spend an afternoon searching thru the tutorials I have listed on that developersdesk.com page. I learned a lot from them... Rick Widmer Internet Marketing Specialists www.developersdesk.com

« previous php.general (#2764) next »