A session class (was Re: [PEAR-DEV] Namespace issues)

From: Date: Fri, 17 May 2002 08:50:53 +0000
Subject: A session class (was Re: [PEAR-DEV] Namespace issues)
References: 1  Groups: php.pear.dev 
Request: Send a blank email to pear-dev+get-6186@lists.php.net to get a copy of this message
le 16/05/02 14:21, Peter Bowyer à reywob@f2s.com a écrit : > At 01:16 PM 5/16/02 +0200, Sebastian Bergmann wrote: >> PHPLIB had a Session class because PHP 3 had no built-in session >> system, like PHP 4 has. There's no point in having a Session class with >> PHP 4. > > You've missed the point totally. There is a marked difference between a > class implementing sessions and a class implementing session management. I agree with that. Of course, it might be overhead in some cases, just like PEAR DB is overhead if you make 2 'selects' in your code and only use MySQL. The authentication system currently in PEAR lacks a good session handler. If you start your session before calling the auth class, you will call session_start two times. Martin could add some code in Auth to handle sessions properly (detect if one is started already, define its timeout, set the cookie name, set the session id...). Today there's nothing like that. For instance, if you want to have a checkbox in your registration form which says 'Remember Me', so that when the user reconnects, he won't have to logon again, it is not possible because you can't set a new cookie with a different expiration date. Also, not having a proper session handler means you have to recode again and again the way you want your session data stored. That won't be a problem if you use MySQL because handlers for this DBS are widely available. But if you use Oracle and need to split your session data because of Oracle limitation on blob size (when not bound) this becomes a problem and you would greatly appreciate a properly written session handler. I don't talk about LDAP and so on. For instance, you might want to store your session data as XML ? A good session handler needs containers. In this way PHPlib session class was good. Auth in PHPLib was depending on the session class. IMO, this is a requirement for a proper authentication system with modern features. And I think this has to be an object because we need to be able to encapsulate and call configuration methods from the outside. I have written on such a class but I am not happy with it and it is not complete. I was only starting to get into OOP when I wrote this. If anyone wrote such a class, even if it is not complete, I would like to see your code... Regards, Bertrand Mansion Mamasam

« previous php.pear.dev (#6186) next »