Re: New features in Auth

From: Date: Wed, 25 Feb 2004 09:40:34 +0000
Subject: Re: New features in Auth
References: 1 2  Groups: php.pear.dev 
Request: Send a blank email to pear-dev+get-25859@lists.php.net to get a copy of this message
Marius Mathiesen wrote:
Well, yes. Or you could check if there _is_ indeed a session established first. If there isn't a session, we implicitly know that the user isn't logged in, right? A quite simple way to check the existence of a session would be to check if the user has presented a cookie with the same name as the session identifier. If you only allow sessions for logged in users, you just have to check for login info in the session data. It *must* be there.
Anyway, my personal method is changing session ids whenever user credentials change. Basically, whenever a logout/login happens, the user is issued a new sessid. Its not like we'll run out of session ids. Cheers, Sérgio

Attachment: [application/pgp-signature] OpenPGP digital signature signature.asc
« previous php.pear.dev (#25859) next »