Re: We need another Auth
| From: | Bertrand Mansion | Date: | Mon, 10 Jun 2002 10:32:12 +0000 |
| Subject: | Re: We need another Auth | ||
| References: | 1 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-6844@lists.php.net to get a copy of this message | ||
le 10/06/02 12:02, Nicolas Hoizey à nhoizey@php.net a écrit :
> Hi,
>
>> this starts to make a lot of exceptions that were not planned in
>> Auth.
>
> I don't see your point on this. Why do you say that the default
> sessions management of PHP used in Auth is an "exception"?
I mean that there are a lot of things that Auth should handle and which it
doesn't. I don't criticise the code neither Martin, the author, who I really
appreciate, but IMO it is not a good thing to have to add hacks outside of a
class especially if you work with other developers on the same project.
>> I corrected the problem by doing a test for the cookie before
>> calling start(). But I can only test for PHPSESSID. What if my
>> cookie variable has a different name.
>
> $cookieName = ini_get('session.name');
OK, you can imagine I do that in my code... But then, someone else might
have changed the session name by using session_name() in which case your
code won't work, I think. Instead, I can use session_name() to retrieve the
session name. I think there should be a way in Auth to know which session
name it uses. That's probably not big deal to code.
Anyway, this was not the point. I think we need to figure out how to know if
a session has already started before we start one. This way, we won't store
unused session files on the server and the auth process could maybe be
faster.
>> Thanks for the tip...
>> You understand the opposite of what I am saying.
>
> You don't have to be rude, I'm just trying to answer and help!
I wasn't rude, sorry if you took it so.
>> I am saying that if someone is not authenticated, I don't want the
>> Auth script to trigger session_start(). There is no reason for that.
>
> OK.
>
>> Of course, you might need sessions for doing something else, in
>> which case you will trigger session_start two times thanks to Auth.
>
> You can call session_start() 10 times if you want, and PHP won't
> create 10 sessions. session_start() should "automagically" know that
> there is already a session started.
I know that. Why doesn't session_start() or something can't tell you that a
session hasn't been started yet or not.
Bertrand Mansion
Mamasam