Re: Session Question

From: Date: Wed, 03 Jan 2001 16:37:18 +0000
Subject: Re: Session Question
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-32511@lists.php.net to get a copy of this message
On Wed, 3 Jan 2001, Paulson, Joseph V. "Jay" wrote: > Hello everyone-- > I've got a strange question for you all today. Let me give you a quick > background as to what is going on. The company I work for uses PHP's > session stored in files to access information etc. The problem is this; > they now want to use Java to access these session files. The thing is that > in the php part of the application I would pass my session id to the Java > servlet and then the Java servlet would use that session id to open the file > on the server and grab the information it needed to run. However, > apparently the Java servlet doesn't have read write permissions to do this. > Is there anyway to set the file properties for the session files in php? I > know this is really insecure but the company won't listen to me or the other > developers who are begging to use a database, they'd rather use the files > (originally they wanted to put all the session info encrypted in the URL and > we all laughed). > > Anyway, any help would be great and if you would like to add an argument for > us to use a database PLEASE let me know what it is. :) > Here's a big arguement: The usual method that PHP uses to encode session information locally is through its internal serialization feature. This is NOT meant to be cross-language. Also, as you have noticed, PHP does not expect to need to give access to any of its session information. Using a database will 1) allow you to use a custom encoding method, and 2) externalize access control. (The serialization problem can be dealt with by using WDDX encoding, but the access problem is a little trickier) What I did was to write a custom session object that controlled the saving and restoring of data to and from a MySQL server running on the web server. It's not a transparent as PHPs built-in session support, but that's not a huge deal. I use serialization for the encoding, but using something different wouldn't be difficult. -- Ignacio Vazquez-Abrams <ignacio@openservices.net>

« previous php.general (#32511) next »