We need another Auth
| From: | Bertrand Mansion | Date: | Mon, 10 Jun 2002 08:49:42 +0000 |
| Subject: | We need another Auth | ||
| References: | 1 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-6835@lists.php.net to get a copy of this message | ||
Hi,
I have had so much difficulties to adapt Auth to my own need. The class is
not flexible enough and might be good for a very basic authentication system
but not for a complete web application.
I think we need a better authentication system.
This morning, I indexed 35 000 pages using htdig on a website I run
(http://cocoa.mamasam.com). The indexing crashed because of the way Auth
handles sessions. I don't understand why there is a session_start() in the
class start() method. This will start a new session everytime htdig accesses
a new page. I ended up with 35 000 session files in the session directory !
This is silly. There might for sure be some other solutions but if so, it is
not explained in the source or in the docs.
It's up to the developer to know if he needs a session_start or not. I don't
get the logic. I don't see why the session should start if the user didn't
bother authenticating. I see a lot of people getting into troubles with this
system. One can make a script that access an Auth protected page and doesn't
accept cookies just like htdig does. Your /tmp or whatever directory will
soon be full with 0K session files.
Excuse me for my anger but I am really pissed of to see that my 5 hours
indexing didn't went well because of that.
BTW, I checked the web for other authentication system and couldn't find any
good one (which works with register_globals off, which handle sessions
correctly, which allows for a 'remember me' checkbox...). If someone has a
link, I will be glad to see it. TIA
Bertrand Mansion
Mamasam