Re: Changing identities of user

From: Date: Wed, 23 Aug 2000 15:17:19 +0000
Subject: Re: Changing identities of user
References: 1  Groups: php.windows 
Request: Send a blank email to php-windows+get-2075@lists.php.net to get a copy of this message
Quintin: QB> Visitors to my website are 'authenticated' by starting a session when they QB> login with their ID as a session variable and checking their identity QB> against a database each time they visit a page carrying confidential QB> information about themselves. QB> I wish to allow *subsequent* visitors to use the same browser 'session' by QB> having earlier users 'logout' and new users 'login' (this is in an QB> environment where terminals are shared). QB> Will some appropriate use of session_destroy() achieve this? I have tried QB> but the user stubbornly insists on remaining the first logged-on user I haven't used sessions, but I have done what you described, using cookies like this: 1. When a user logs in (login), I set a cookie with its User ID: --> setcookie('cookie_userid',$UserID); this MUST be done before your script sends any output, otherwise it will not work. 2. On every page I check if the variable $cookie_userid exists: --> if (isset($cookie_userid)) { do whatever is necessary, ... } else { redirect to login page } 3. When user logs out (logout), I destroy the cookie: --> setcookie('cookie_userid'); again, this must be done before any output is sent. If you wish to have an auto-logout feature, that is, to force logout after a certain interval of inactivity, you can set the cookie with a timeout, modify step 1 to: --> setcookie('cookie_userid',$UserID,time()+300); this means that the cookie will expire on time() plus 300 seconds, that is, in five minutes. In this case, you MUST also reset the cookie on every page, so that the timeout is moved forward on every use, modify step 2 to: --> if (isset($cookie_userid)) { setcookie('cookie_userid',$UserID,time()+300); ... do whatever is necessary, ... } else { redirect to login page } Always remember to set the cookie before any html output to the browser. QB> Some hints on how to control caching of confidential pages in these QB> circumstances would also be welcome! From the PHP Manual, XX. HTML functions, header() --- PHP scripts often generate dynamic HTML that must not be cached by the client browser or any proxy caches between the server and the client browser. Many proxies and clients can be forced to disable caching with: 1 2 header ("Expires: Mon, 26 Jul 1997 05:00:00 GMT"); // Date in the past 3 header ("Last-Modified: " . gmdate("D, d M Y H:i:s") . " GMT"); 4 // always modified 5 header ("Cache-Control: no-cache, must-revalidate"); // HTTP/1.1 6 header ("Pragma: no-cache"); // HTTP/1.0 7 The header function MUST also be used before any output is sent to the browser. Hope this helps, Saludos, Pablo Vera

« previous php.windows (#2075) next »