Re: We need another Auth
| From: | Pierre-Alain Joye | Date: | Mon, 10 Jun 2002 09:26:59 +0000 |
| Subject: | Re: We need another Auth | ||
| References: | 1 2 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-6837@lists.php.net to get a copy of this message | ||
On Mon, 10 Jun 2002 10:49:42 +0200
Bertrand Mansion <bmansion@mamasam.com> wrote:
> Hi,
>
> I have had so much difficulties to adapt Auth to my own need. The class is
> not flexible enough and might be good for a very basic authentication system
> but not for a complete web application.
>
> I think we need a better authentication system.
>
> This morning, I indexed 35 000 pages using htdig on a website I run
> (http://cocoa.mamasam.com). The indexing crashed because of the way Auth
> handles sessions. I don't understand why there is a session_start() in the
> class start() method. This will start a new session everytime htdig accesses
> a new page. I ended up with 35 000 session files in the session directory !
Heu, I just believe session_start() start a new session only if no old one exists. If there is
already a session, session_start() reload the data owned by the active session. I think htdig does
not manage cookie natively but maybe you can play with the block and the PHPSID propagation
(--enable-trans-sid).
> This is silly. There might for sure be some other solutions but if so, it is
> not explained in the source or in the docs.
As far I remember the docs, Auth uses session and it relatively logic to use the php native
functions ?
hth
pa