Re: We need another Auth

From: Date: Mon, 10 Jun 2002 10:39:21 +0000
Subject: Re: We need another Auth
References: 1  Groups: php.pear.dev 
Request: Send a blank email to pear-dev+get-6845@lists.php.net to get a copy of this message
le 10/06/02 11:52, Markus Wolff à wolff@21st.de a écrit : > Am Mon, 10 Jun 2002 11:45:03 +0200 schrieb Bertrand Mansion > <bmansion@mamasam.com>: > >> You understand the opposite of what I am saying. I am saying that if someone >> is not authenticated, I don't want the Auth script to trigger >> session_start(). There is no reason for that. He is just not authenticated >> and that's all, I don't need to start a new session to know that, do I ? > > That may be correct if you´re using HTTP authentication - with that you > can check if the user is authenticated in general and if yes, start the > session and get this user´s access rights or other user specific data > out of the session. > > But... what if you don´t use HTTP auth? What if your authentication is > solely based on sessions? I.e. user object is in session and login flag > is true == yes, he´s authenticated. User object is not in session and/or > login flag is false == authentication failed. > > You wouldn´t have a chance to determine if a user is authenticated > without starting a session first. Which I find silly and not logical. Why would you want to check if a user is authenticated if he doesn't even has a session started. That's a supplementary step and add overhead to both your code and your filesystem (if you are using file handler). I know there is no way to know if a session is started without starting one yourself but this doesn't mean it is good. There might be a workaround : you start your session, if it is empty, you unset and destroy it. The objective for me being that I don't want to store session files for users that don't need the 'remember me' feature. How do you handle this in your new auth class ? Bertrand Mansion Mamasam

« previous php.pear.dev (#6845) next »