Re: We need another Auth
| From: | Markus Wolff | Date: | Mon, 10 Jun 2002 09:52:03 +0000 |
| Subject: | Re: We need another Auth | ||
| References: | 1 2 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-6840@lists.php.net to get a copy of this message | ||
Am Mon, 10 Jun 2002 11:45:03 +0200 schrieb Bertrand Mansion <bmansion@mamasam.com>:
> You understand the opposite of what I am saying. I am saying that if someone
> is not authenticated, I don't want the Auth script to trigger
> session_start(). There is no reason for that. He is just not authenticated
> and that's all, I don't need to start a new session to know that, do I ?
That may be correct if you´re using HTTP authentication - with that you
can check if the user is authenticated in general and if yes, start the
session and get this user´s access rights or other user specific data
out of the session.
But... what if you don´t use HTTP auth? What if your authentication is
solely based on sessions? I.e. user object is in session and login flag
is true == yes, he´s authenticated. User object is not in session and/or
login flag is false == authentication failed.
You wouldn´t have a chance to determine if a user is authenticated
without starting a session first.
Regards,
Markus
--
*21st Media* | Consulting, Konzeption, Produktion für die Bereiche:
Markus Wolff | Internet, Intranet, eCommerce, Content Management,
Hamburg,Germany | Softwareentwicklung, 3D-Animation, Videostreaming
http://21st.de | Tel. [+49](0)40/6887949-0, Fax: [+49](0)40/6887949-1