Re: We need another Auth
| From: | Bertrand Mansion | Date: | Mon, 10 Jun 2002 10:39:21 +0000 |
| Subject: | Re: We need another Auth | ||
| References: | 1 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-6845@lists.php.net to get a copy of this message | ||
le 10/06/02 11:52, Markus Wolff à wolff@21st.de a écrit :
> Am Mon, 10 Jun 2002 11:45:03 +0200 schrieb Bertrand Mansion
> <bmansion@mamasam.com>:
>
>> You understand the opposite of what I am saying. I am saying that if someone
>> is not authenticated, I don't want the Auth script to trigger
>> session_start(). There is no reason for that. He is just not authenticated
>> and that's all, I don't need to start a new session to know that, do I ?
>
> That may be correct if you´re using HTTP authentication - with that you
> can check if the user is authenticated in general and if yes, start the
> session and get this user´s access rights or other user specific data
> out of the session.
>
> But... what if you don´t use HTTP auth? What if your authentication is
> solely based on sessions? I.e. user object is in session and login flag
> is true == yes, he´s authenticated. User object is not in session and/or
> login flag is false == authentication failed.
>
> You wouldn´t have a chance to determine if a user is authenticated
> without starting a session first.
Which I find silly and not logical.
Why would you want to check if a user is authenticated if he doesn't even
has a session started. That's a supplementary step and add overhead to both
your code and your filesystem (if you are using file handler).
I know there is no way to know if a session is started without starting one
yourself but this doesn't mean it is good. There might be a workaround : you
start your session, if it is empty, you unset and destroy it.
The objective for me being that I don't want to store session files for
users that don't need the 'remember me' feature. How do you handle this in
your new auth class ?
Bertrand Mansion
Mamasam