Re: We need another Auth
| From: | Bertrand Mansion | Date: | Mon, 10 Jun 2002 10:13:06 +0000 |
| Subject: | Re: We need another Auth | ||
| References: | 1 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-6842@lists.php.net to get a copy of this message | ||
le 10/06/02 11:45, Markus Wolff à wolff@21st.de a écrit :
> Am Mon, 10 Jun 2002 10:49:42 +0200 schrieb Bertrand Mansion
> <bmansion@mamasam.com>:
>
>> I think we need a better authentication system.
>
> We had a small discussion about that last week (I think). In short, yes
> we do.
>
> I´ve developed a user authentication and rights management system that
> can be used in almost every environment and that I´m currently rewriting
> to be independent of a specific datasource (before, you could store user
> data only in MySQL, with the new version you´ll be able to use any
> database, LDAP server or even a SOAP webservice for user authentication).
>
> When I´m done (most likely by the end of this week), I´ll post a link to
> the sources and API doc so that it can be considered for inclusion in
> PEAR.
>
>> This morning, I indexed 35 000 pages using htdig on a website I run
>> (http://cocoa.mamasam.com). The indexing crashed because of the way Auth
>> handles sessions. I don't understand why there is a session_start() in the
>> class start() method. This will start a new session everytime htdig accesses
>> a new page. I ended up with 35 000 session files in the session directory !
>>
>> This is silly. There might for sure be some other solutions but if so, it is
>> not explained in the source or in the docs.
>
> Good point. I wrote a login manager class for my authentication system
> that does the same thing, but I didn´t think about indexers (actually
> you don´t _have_ to use the manager class to use the authentication
> system, but it makes things a LOT more convenient).
>
> Question is: How does one solve the authentication problem without using
> a session?
I think that if the session is not started it means the user is not
authenticated. There is no point going any step further in the
authentication process. Now the question is: how do you know if a session
has been started. I have done so by checking for the PHPSESSID cookie. If it
is set, then the session exists, then I can go further. The problem here is
that the cookie name is hardcoded and should probably not. It should be a
parameter in the Auth class. I don't know if there is a way to know if a
session exist without starting a session (?). You can probably get the
session name by using php session_name() function and check against that.
You might also want to check if there is anything stored in $_SESSION.
There are all sort of possibilities, it's up to us to find the most
appropriate.
If you use a 'remember me' button, you will have to store the session
somewhere for later use. But if the Garbage Collector for session files is
set to one hour or so, you can say goodbye to your session file. And when
the user will come back, he will not be remembered. I have thought about
putting a md5 hash of the user+password values in the cookie instead of the
md5 hash of the session id but this means you have to create a special field
with the same value in your user database and check against that.
Anyway, this doesn't solve the 'remember me' problem. If you want to
remember a user for one year, you will have to keep his session one year
somewhere on your server. I am sure there is a better way for that.
>> BTW, I checked the web for other authentication system and couldn't find any
>> good one (which works with register_globals off, which handle sessions
>> correctly, which allows for a 'remember me' checkbox...). If someone has a
>> link, I will be glad to see it. TIA
>
> The abovementioned system handles all these cases, I´m just not sure if
> it´ll match your definition of handling sessions correctly (some more
> insight in what you think would be proper handling might help). And as I
> said, I´ll propose it by the end of this week for inclusion in PEAR.
Great !
You can count on me to review your code :-) and help you with it if you need
some help.
Handling sessions correctly, is, as I explain above, to know if a session as
already been started, if yes, to use it, if no, to not start a new one and
to stop the auth process here. That's almost it for now :-)
Let me know when I can see the code...
Bertrand Mansion
Mamasam