Re: liveUser: changing permissions for active sessions
| From: | Markus Wolff | Date: | Mon, 19 Aug 2002 12:26:52 +0000 |
| Subject: | Re: liveUser: changing permissions for active sessions | ||
| References: | 1 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-8503@lists.php.net to get a copy of this message | ||
Am Mon, 19 Aug 2002 14:18:45 +0200 schrieb "Lukas Smith" <smith@dybnet.de>:
> The real problem is that liveUser currently does not have a mechanism to
> change the permissions of active sessions, since the permissions of each
> user are stored in a session.
>
> So how to best go about solving this problem?
> I have asked several people on IRC about this
>
> 1) when the rights are changed, check all active sessions if any of them
> are affected by this change. Modify all affected sessions accordingly.
>
> 2) when the rights are changed, check all active sessions if any of them
> are affected by this change. Set a flag that is read at every loading of
> the page that tells liveUser to re-read the permissions, or maybe even
> just modify the existing array that stores all the permissions
You forgot to mention the very-simple-but-ultra-ugly third possibility:
3) Save the currently active session ID for the user in the database
at each login. When changing rights, look which users are affected
and which session IDs they currently have. After that:
Delete those sessions entirely!
This is of course the quickest and easiest-to-implement way of doing it
but comes with the disadvantage important session data other than
permissions will be gone as well.
Regards,
Markus
--
*21st Media* | Consulting, Konzeption, Produktion für die Bereiche:
Markus Wolff | Internet, Intranet, eCommerce, Content Management,
Hamburg,Germany | Softwareentwicklung, 3D-Animation, Videostreaming
http://21st.de | Tel. [+49](0)40/6887949-0, Fax: [+49](0)40/6887949-1