Re: Re: Question about cookies
| From: | Pieter Westland | Date: | Tue, 27 Jun 2000 12:50:48 +0000 |
| Subject: | Re: Re: Question about cookies | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-3324@lists.php.net to get a copy of this message | ||
On Tue, Jun 27, 2000 at 11:22:30AM +1200, Stephen Cope wrote:
> : I want to create some scripting in which a user can access for 1 minute,
> : after the minute has expired he has to relogin. Things are configured
> : using a cookie.
>
> Why such a short time period? Your server time and the time on their
> computer clock is probably out by at least a few seconds, so when you factor
> in delays with HTTP requests, then there is only a very slim margin of time
> in which they will be able to use this particular page.
Yes of course, this period should be more, but for testing purposes I set
it low.
> I also don't understand your code.
>
> It works like so:
>
> * if there is no cookie, remove their login details
> * if there are no login details, as for their login details
> * store a cookie
That's right!
> I think your code needs a bit of a rewrite to look more like so:
>
> <?php
>
> # this is uneccessary.
> #if (!$testcookie) {
> #unset($PHP_AUTH_USER);
> #}
>
> # changed this slightly (so we are not testing
> # undefined variables, a bad thing (and a warning in PHP4)):
> if (!isset($PHP_AUTH_USER) && !$PHP_AUTH_USER) {
> Header("WWW-authenticate: basic realm=\"Testsite\"");
> Header("HTTP/1.0 401 Unauthorized");
> echo "<body bgcolor=#ffffff>Cancel... (not logged in).\n"; exit;
> }
>
> # this is new
> else {
>
> setcookie ("testcookie", "foobar",time()+60); /* expire in 1 minute */
> echo "logged in";
>
> # and so is this
> }
> ?>
This works, thank you... but where is checked now if the cookie exists,
and are the login details resetted when there's no cookie present?
Pieter