Ideas on Auth, pls advise
| From: | jsWalter | Date: | Mon, 01 Sep 2003 22:36:57 +0000 |
| Subject: | Ideas on Auth, pls advise | ||
| Groups: | php.pear.dev | ||
| Request: | Send a blank email to pear-dev+get-20980@lists.php.net to get a copy of this message | ||
I just added 'loginAttempt' as a session variable in Auth.
well, not 'in' it, but in my login and verification code outside the class
(see code below)
What I'd like to do is have the class handle this all on its own.
This is what I see should (could, might?) happen...
- new session
- set 'loginAttempt' to ZERO
- if current session AND user not logged in
- see if current count is != maxAttempt (see below)
- if yes, increment 'loginAttempt'
- if no, run 'failedLogin' <- new method, in line with 'drawLogin'
- at successful log in - set 'loginAttempt' to ZERO
- be able to set max attempts...
$auth->maxAttempts = 3;
I know how to add that variable to the class. Do so infact to mine.
Since I'm not all that good at OOP (yet) and I'd rather ask then tell right
now, can someone who knows AUTH Class please advise on how best to do this?
I'd like to do this for my copy at least. Besides, it will help me grok PHP
OOP.
Thanks
Walter
BTW: To make my attempt counter work, I had to add 'session_destroy();' to
logout method...
if (isset($_SESSION)) {
unset($session[$this->_sessionName]);
session_destroy();
} else {
session_unregister($this->_sessionName);
session_destroy();
}
What will this break?
=-=============================================
// A database is used as storage container in this example
$objAuth = &new Auth("DB", $params);
// Define login method - don't show it!
$objAuth->showLogin = false;
// Define maximum login attempts
$objAuth->maxAttempts = 3;
// Set Session login attempt counter
if (! $objAuth->getAuthData('loginAttempt'))
$objAuth->setAuthData('loginAttempt', '0');
... other code
if ($objAuth->getAuth())
{
// We're in! Now go somewhere else!
header("Location:success.php");
}
else
{
if (isset($_REQUEST['act']) && ($_REQUEST['act'] ==
'login'))
{
echo '<div>Unsuccessful attempt, please try again.<p /></div>';
}
if ($objAuth->getAuthData('loginAttempt') != $objAuth->maxAttempts )
$objAuth->setAuthData('loginAttempt',
($objAuth->getAuthData('loginAttempt') + 1));
else
header("Location:failed.php");
}
// Login HTML Form goes here