RE: [PEAR-DEV] We need another Auth
| From: | LIMBOURG Arnaud | Date: | Mon, 10 Jun 2002 11:54:31 +0000 |
| Subject: | RE: [PEAR-DEV] We need another Auth | ||
| Groups: | php.pear.dev | ||
| Request: | Send a blank email to pear-dev+get-6856@lists.php.net to get a copy of this message | ||
> Which I find silly and not logical.
> Why would you want to check if a user is authenticated if he
> doesn't even
> has a session started. That's a supplementary step and add
> overhead to both
> your code and your filesystem (if you are using file handler).
>
> I know there is no way to know if a session is started
> without starting one
> yourself but this doesn't mean it is good. There might be a
> workaround : you
> start your session, if it is empty, you unset and destroy it.
>
> The objective for me being that I don't want to store session
> files for
> users that don't need the 'remember me' feature. How do you
> handle this in
> your new auth class ?
For the remember me feature, you have to store info in a cookie on the
client side. How else would you know who is who ?
If cookies are disabled i don't see how you can have a remember me feature.
Maybe i'm completely wrong here so indulge me ;)
> Bertrand Mansion
> Mamasam