A session class (was Re: [PEAR-DEV] Namespace issues)
| From: | Bertrand Mansion | Date: | Fri, 17 May 2002 08:50:53 +0000 |
| Subject: | A session class (was Re: [PEAR-DEV] Namespace issues) | ||
| References: | 1 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-6186@lists.php.net to get a copy of this message | ||
le 16/05/02 14:21, Peter Bowyer à reywob@f2s.com a écrit :
> At 01:16 PM 5/16/02 +0200, Sebastian Bergmann wrote:
>> PHPLIB had a Session class because PHP 3 had no built-in session
>> system, like PHP 4 has. There's no point in having a Session class with
>> PHP 4.
>
> You've missed the point totally. There is a marked difference between a
> class implementing sessions and a class implementing session management.
I agree with that.
Of course, it might be overhead in some cases, just like PEAR DB is overhead
if you make 2 'selects' in your code and only use MySQL.
The authentication system currently in PEAR lacks a good session handler. If
you start your session before calling the auth class, you will call
session_start two times. Martin could add some code in Auth to handle
sessions properly (detect if one is started already, define its timeout, set
the cookie name, set the session id...).
Today there's nothing like that.
For instance, if you want to have a checkbox in your registration form which
says 'Remember Me', so that when the user reconnects, he won't have to logon
again, it is not possible because you can't set a new cookie with a
different expiration date.
Also, not having a proper session handler means you have to recode again and
again the way you want your session data stored. That won't be a problem if
you use MySQL because handlers for this DBS are widely available. But if you
use Oracle and need to split your session data because of Oracle limitation
on blob size (when not bound) this becomes a problem and you would greatly
appreciate a properly written session handler. I don't talk about LDAP and
so on. For instance, you might want to store your session data as XML ?
A good session handler needs containers.
In this way PHPlib session class was good. Auth in PHPLib was depending on
the session class. IMO, this is a requirement for a proper authentication
system with modern features.
And I think this has to be an object because we need to be able to
encapsulate and call configuration methods from the outside.
I have written on such a class but I am not happy with it and it is not
complete. I was only starting to get into OOP when I wrote this.
If anyone wrote such a class, even if it is not complete, I would like to
see your code...
Regards,
Bertrand Mansion
Mamasam