Re: We need another Auth
| From: | Markus Wolff | Date: | Mon, 10 Jun 2002 10:53:07 +0000 |
| Subject: | Re: We need another Auth | ||
| References: | 1 2 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-6848@lists.php.net to get a copy of this message | ||
Am Mon, 10 Jun 2002 12:39:21 +0200 schrieb Bertrand Mansion <bmansion@mamasam.com>:
> > But... what if you don´t use HTTP auth? What if your authentication is
> > solely based on sessions? I.e. user object is in session and login flag
> > is true == yes, he´s authenticated. User object is not in session and/or
> > login flag is false == authentication failed.
> >
> > You wouldn´t have a chance to determine if a user is authenticated
> > without starting a session first.
>
> Which I find silly and not logical.
> Why would you want to check if a user is authenticated if he doesn't even
> has a session started. That's a supplementary step and add overhead to both
> your code and your filesystem (if you are using file handler).
That depends on your application - if it uses sessions for other things,
too it really doesn´t matter. But of course you´re right when you say
that a session shouldn´t be started if none is needed.
I think I am beginning to understand what you want and I guess I also
already have an idea how to implement it in my auth system.
> The objective for me being that I don't want to store session files for
> users that don't need the 'remember me' feature. How do you handle this in
> your new auth class ?
As you mentioned in an earlier posting, storing the 'remember me' option
in the session wouldn´t make too much sense, because when garbage
collection is done, the session is gone and you´ll have to
re-authenticate again.
I use a separate cookie with the user´s handle in it. If that cookie is
present, the user is authenticated automatically without having to
provide a password. As this generally is risky business, you can turn
this feature off, which is the standard setting. Also, all cookie
parameters (name, path, domain, expiration date) can be freely
configured (as well as session name, session variable name, parameter
names for handle/password input and anything else that makes sense to be
configurable).
Regards,
Markus
--
*21st Media* | Consulting, Konzeption, Produktion für die Bereiche:
Markus Wolff | Internet, Intranet, eCommerce, Content Management,
Hamburg,Germany | Softwareentwicklung, 3D-Animation, Videostreaming
http://21st.de | Tel. [+49](0)40/6887949-0, Fax: [+49](0)40/6887949-1