Re: New features in Auth
| From: | Sérgio Carvalho | Date: | Wed, 25 Feb 2004 09:40:34 +0000 |
| Subject: | Re: New features in Auth | ||
| References: | 1 2 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-25859@lists.php.net to get a copy of this message | ||
Marius Mathiesen wrote:
Attachment: [application/pgp-signature] OpenPGP digital signature signature.asc
Well, yes. Or you could check if there _is_ indeed a session established first. If there isn't a session, we implicitly know that the user isn't logged in, right? A quite simple way to check the existence of a session would be to check if the user has presented a cookie with the same name as the session identifier. If you only allow sessions for logged in users, you just have to check for login info in the session data. It *must* be there.Anyway, my personal method is changing session ids whenever user credentials change. Basically, whenever a logout/login happens, the user is issued a new sessid. Its not like we'll run out of session ids. Cheers, Sérgio
Attachment: [application/pgp-signature] OpenPGP digital signature signature.asc