Re: We need another Auth

From: Date: Mon, 10 Jun 2002 09:52:03 +0000
Subject: Re: We need another Auth
References: 1 2  Groups: php.pear.dev 
Request: Send a blank email to pear-dev+get-6840@lists.php.net to get a copy of this message
Am Mon, 10 Jun 2002 11:45:03 +0200 schrieb Bertrand Mansion <bmansion@mamasam.com>: > You understand the opposite of what I am saying. I am saying that if someone > is not authenticated, I don't want the Auth script to trigger > session_start(). There is no reason for that. He is just not authenticated > and that's all, I don't need to start a new session to know that, do I ? That may be correct if you´re using HTTP authentication - with that you can check if the user is authenticated in general and if yes, start the session and get this user´s access rights or other user specific data out of the session. But... what if you don´t use HTTP auth? What if your authentication is solely based on sessions? I.e. user object is in session and login flag is true == yes, he´s authenticated. User object is not in session and/or login flag is false == authentication failed. You wouldn´t have a chance to determine if a user is authenticated without starting a session first. Regards, Markus -- *21st Media* | Consulting, Konzeption, Produktion für die Bereiche: Markus Wolff | Internet, Intranet, eCommerce, Content Management, Hamburg,Germany | Softwareentwicklung, 3D-Animation, Videostreaming http://21st.de | Tel. [+49](0)40/6887949-0, Fax: [+49](0)40/6887949-1

« previous php.pear.dev (#6840) next »