Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > comp.lang.php > #17743

Re: php ini

From Thomas 'PointedEars' Lahn <PointedEars@web.de>
Newsgroups comp.lang.php
Subject Re: php ini
Date 2018-05-16 19:59 +0200
Organization PointedEars Software (PES)
Message-ID <13761023.FnKYLD8mAL@PointedEars.de> (permalink)
References <pdh718$u78$1@dont-email.me> <pdhfpq$l5h$1@dont-email.me> <1731736.ES7vfGFGlS@PointedEars.de> <pdhkmp$s7c$1@dont-email.me>

Show all headers | View raw


Lew Pitcher wrote:

> Thomas 'PointedEars' Lahn wrote:
>> Lew Pitcher wrote:
>>> You are looking for the "session.cookie_lifetime" setting in php.ini
>> 
>> Not necessarily.

Because that setting is not the only one that controls the availability of 
session information.

>>> […]
>>>   http://php.net/manual/en/session.configuration.php
>>> 
>>> [snip]
>>> 
>>> FWIW, this is a global php setting;
>> 
>> It does not have to.
> 
> Yes, it does.
> 
> You can /override/ the setting, but that takes a deliberate act.

I would assume that depends on how the PHP executable is compiled.
 
>>> if you have multiple pages,
>> You mean Web _sites_.
> 
> No, I mean multiple pages.

First of all, *there* *are* *no* (*Web*) *pages*.  Get rid of that outdated 
concept NOW.

Second, it is a bad idea for different parts of the same Web site to have 
different session lifetimes, unless they are part of distinct applications 
that are presented as such to the user.

Even then, users usually expect a Web site, and in a broader context, a Web 
application as a service to other Web resources, to work consistently 
throughout.  If the session is the result of a login process, they will not 
appreciate that this session times out earlier in one section of the Web 
site or one feature of the Web service than in another.
 
>>> each with their own session criteria, you can override this default by
>>> passing the appropriate value in the session_start() call.
    ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
>> (They said that they do not want to do it in code.)
> 
> Yes, so?

So this particular suggestion is the exact opposite of what the OP is 
looking for.  (Is that not blatantly obvious?)

One valid reason why one would not want to do it in code is that the code 
must not or is not supposed to be modified.

> My answer stands: use the "session.cookie_lifetime" setting in
> php.ini

If one does that, then that affects all parts of all sites hosted on the 
same (virtual) server.  Bad idea, and often not even possible as prevented 
by administrative locks.
 
>> Provide an additional configuration (file) for each site instead.
> 
> What sort of "configuration (file)"?

This setting and many other session-related settings have a changeable mode 
of PHP_INI_ALL, which means that they can be set in php.ini and in PHP 
source code, but also in httpd.conf (including the virtual host 
configuration), and per directory in a .htaccess or .user.ini file 
(therefore, “file” in parentheses).

> And, how do /you/ control separate sessions per page (yes, you /can/ do
> that)?

That depends on what *you* mean by “page”.  This term is underdefined at 
best.

For different dynamically generated Web documents, that belong to the same 
application, I would not do it.

For distinct applications, using different session.save_path, which also can 
be be set in one of the ways that I described above; preferably _not_ in 
php.ini or code.  In fact, different session directiories is the recommended 
approach, so that different sessions of different applications on the same 
server do not interfere, can expire, be garbage collected, and be reset 
manually if necessary, independently.

-- 
PointedEars
Zend Certified PHP Engineer <http://www.zend.com/en/yellow-pages/ZEND024953>
<https://github.com/PointedEars> | <http://PointedEars.de/wsvn>
Twitter: @PointedEars2 | Please do not cc me./Bitte keine Kopien per E-Mail.

Back to comp.lang.php | Previous | NextPrevious in thread | Next in thread | Find similar | Unroll thread


Thread

php ini madwomans Dad <dsvirtual58@gmail.com> - 2018-05-16 13:09 +0100
  Re: php ini tony@mountifield.org (Tony Mountifield) - 2018-05-16 13:11 +0000
    Re: php ini K <yyyyyeeeee00000@writeme.com> - 2023-03-11 07:53 -0800
      Re: php ini doctor@doctor.nl2k.ab.ca (The Doctor) - 2023-03-11 23:44 +0000
  Re: php ini Lew Pitcher <lew.pitcher@digitalfreehold.ca> - 2018-05-16 10:38 -0400
    Re: php ini Thomas 'PointedEars' Lahn <PointedEars@web.de> - 2018-05-16 16:53 +0200
      Re: php ini Lew Pitcher <lew.pitcher@digitalfreehold.ca> - 2018-05-16 12:02 -0400
        Re: php ini Thomas 'PointedEars' Lahn <PointedEars@web.de> - 2018-05-16 19:59 +0200
          Re: php ini Jerry Stuckle <jstucklex@attglobal.net> - 2018-05-16 15:09 -0400
    Re: php ini "J.O. Aho" <user@example.net> - 2018-05-16 18:29 +0200
  Re: php ini Thomas 'PointedEars' Lahn <PointedEars@web.de> - 2018-05-16 16:48 +0200
    Re: php ini "J.O. Aho" <user@example.net> - 2018-05-16 18:36 +0200
  Re: php ini madwomans Dad <dsvirtual58@gmail.com> - 2018-05-17 08:42 +0100

csiph-web