Re: Changing identities of user
| From: | Pablo Vera | Date: | Wed, 23 Aug 2000 15:17:19 +0000 |
| Subject: | Re: Changing identities of user | ||
| References: | 1 | Groups: | php.windows |
| Request: | Send a blank email to php-windows+get-2075@lists.php.net to get a copy of this message | ||
Quintin:
QB> Visitors to my website are 'authenticated' by starting a session when they
QB> login with their ID as a session variable and checking their identity
QB> against a database each time they visit a page carrying confidential
QB> information about themselves.
QB> I wish to allow *subsequent* visitors to use the same browser 'session' by
QB> having earlier users 'logout' and new users 'login' (this is in an
QB> environment where terminals are shared).
QB> Will some appropriate use of session_destroy() achieve this? I have tried
QB> but the user stubbornly insists on remaining the first logged-on user
I haven't used sessions, but I have done what you described, using
cookies like this:
1. When a user logs in (login), I set a cookie with its User ID:
--> setcookie('cookie_userid',$UserID);
this MUST be done before your script sends any output, otherwise it
will not work.
2. On every page I check if the variable $cookie_userid exists:
--> if (isset($cookie_userid)) {
do whatever is necessary, ...
} else {
redirect to login page
}
3. When user logs out (logout), I destroy the cookie:
--> setcookie('cookie_userid');
again, this must be done before any output is sent.
If you wish to have an auto-logout feature, that is, to force logout
after a certain interval of inactivity, you can set the cookie with a
timeout, modify step 1 to:
--> setcookie('cookie_userid',$UserID,time()+300);
this means that the cookie will expire on time() plus 300 seconds,
that is, in five minutes.
In this case, you MUST also reset the cookie on every page, so that
the timeout is moved forward on every use, modify step 2 to:
--> if (isset($cookie_userid)) {
setcookie('cookie_userid',$UserID,time()+300);
...
do whatever is necessary, ...
} else {
redirect to login page
}
Always remember to set the cookie before any html output to the
browser.
QB> Some hints on how to control caching of confidential pages in these
QB> circumstances would also be welcome!
From the PHP Manual, XX. HTML functions, header() ---
PHP scripts often generate dynamic HTML that must not be cached by the
client browser or any proxy caches between the server and the client
browser. Many proxies and clients can be forced to disable caching
with:
1
2 header ("Expires: Mon, 26 Jul 1997 05:00:00 GMT"); // Date in the past
3 header ("Last-Modified: " . gmdate("D, d M Y H:i:s") . " GMT");
4 // always modified
5 header ("Cache-Control: no-cache, must-revalidate"); // HTTP/1.1
6 header ("Pragma: no-cache"); // HTTP/1.0
7
The header function MUST also be used before any output is sent to the
browser.
Hope this helps,
Saludos,
Pablo Vera