Re: Session Question
| From: | Ignacio Vazquez-Abrams | Date: | Wed, 03 Jan 2001 16:37:18 +0000 |
| Subject: | Re: Session Question | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-32511@lists.php.net to get a copy of this message | ||
On Wed, 3 Jan 2001, Paulson, Joseph V. "Jay" wrote:
> Hello everyone--
> I've got a strange question for you all today. Let me give you a quick
> background as to what is going on. The company I work for uses PHP's
> session stored in files to access information etc. The problem is this;
> they now want to use Java to access these session files. The thing is that
> in the php part of the application I would pass my session id to the Java
> servlet and then the Java servlet would use that session id to open the file
> on the server and grab the information it needed to run. However,
> apparently the Java servlet doesn't have read write permissions to do this.
> Is there anyway to set the file properties for the session files in php? I
> know this is really insecure but the company won't listen to me or the other
> developers who are begging to use a database, they'd rather use the files
> (originally they wanted to put all the session info encrypted in the URL and
> we all laughed).
>
> Anyway, any help would be great and if you would like to add an argument for
> us to use a database PLEASE let me know what it is. :)
>
Here's a big arguement:
The usual method that PHP uses to encode session information locally is
through its internal serialization feature. This is NOT meant to be
cross-language. Also, as you have noticed, PHP does not expect to need to give
access to any of its session information. Using a database will 1) allow you
to use a custom encoding method, and 2) externalize access control.
(The serialization problem can be dealt with by using WDDX encoding, but the
access problem is a little trickier)
What I did was to write a custom session object that controlled the saving and
restoring of data to and from a MySQL server running on the web server. It's
not a transparent as PHPs built-in session support, but that's not a huge
deal. I use serialization for the encoding, but using something different
wouldn't be difficult.
--
Ignacio Vazquez-Abrams <ignacio@openservices.net>