Re: We need another Auth

From: Date: Mon, 10 Jun 2002 10:53:07 +0000
Subject: Re: We need another Auth
References: 1 2  Groups: php.pear.dev 
Request: Send a blank email to pear-dev+get-6848@lists.php.net to get a copy of this message
Am Mon, 10 Jun 2002 12:39:21 +0200 schrieb Bertrand Mansion <bmansion@mamasam.com>: > > But... what if you don´t use HTTP auth? What if your authentication is > > solely based on sessions? I.e. user object is in session and login flag > > is true == yes, he´s authenticated. User object is not in session and/or > > login flag is false == authentication failed. > > > > You wouldn´t have a chance to determine if a user is authenticated > > without starting a session first. > > Which I find silly and not logical. > Why would you want to check if a user is authenticated if he doesn't even > has a session started. That's a supplementary step and add overhead to both > your code and your filesystem (if you are using file handler). That depends on your application - if it uses sessions for other things, too it really doesn´t matter. But of course you´re right when you say that a session shouldn´t be started if none is needed. I think I am beginning to understand what you want and I guess I also already have an idea how to implement it in my auth system. > The objective for me being that I don't want to store session files for > users that don't need the 'remember me' feature. How do you handle this in > your new auth class ? As you mentioned in an earlier posting, storing the 'remember me' option in the session wouldn´t make too much sense, because when garbage collection is done, the session is gone and you´ll have to re-authenticate again. I use a separate cookie with the user´s handle in it. If that cookie is present, the user is authenticated automatically without having to provide a password. As this generally is risky business, you can turn this feature off, which is the standard setting. Also, all cookie parameters (name, path, domain, expiration date) can be freely configured (as well as session name, session variable name, parameter names for handle/password input and anything else that makes sense to be configurable). Regards, Markus -- *21st Media* | Consulting, Konzeption, Produktion für die Bereiche: Markus Wolff | Internet, Intranet, eCommerce, Content Management, Hamburg,Germany | Softwareentwicklung, 3D-Animation, Videostreaming http://21st.de | Tel. [+49](0)40/6887949-0, Fax: [+49](0)40/6887949-1

« previous php.pear.dev (#6848) next »