Path: csiph.com!x330-a1.tempe.blueboxinc.net!usenet.pasdenom.info!weretis.net!feeder4.news.weretis.net!eternal-september.org!feeder.eternal-september.org!.POSTED!not-for-mail From: Arno Welzel Newsgroups: comp.lang.php Subject: Re: session handler auto log out Date: Wed, 23 Nov 2011 10:17:45 +0100 Organization: A noiseless patient Spider Lines: 85 Message-ID: <4ECCBA39.9070501@arnowelzel.de> References: <11984037.1120.1321742991368.JavaMail.geo-discussion-forums@prlm15> <4ECA5B14.5020200@arnowelzel.de> <4ECA60DE.6070301@arnowelzel.de> <4ECB82D1.2000902@arnowelzel.de> <4ECBC5FC.4050306@arnowelzel.de> Mime-Version: 1.0 Content-Type: text/plain; charset=ISO-8859-1 Content-Transfer-Encoding: 7bit Injection-Info: mx04.eternal-september.org; posting-host="dmYg0DIsuEi3Fj+mt8IKsg"; logging-data="20246"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX19cMECXNjkzdAvrybgk0pKq1xNHn5ysZgs=" User-Agent: Mozilla/5.0 (Windows NT 5.1; rv:8.0) Gecko/20111105 Thunderbird/8.0 In-Reply-To: Cancel-Lock: sha1:2E6KQcsmciRRAz3hz11lLR2FrqI= Xref: x330-a1.tempe.blueboxinc.net comp.lang.php:3884 Jerry Stuckle, 2011-11-22 19:18: > On 11/22/2011 10:55 AM, Arno Welzel wrote: >> Jerry Stuckle, 2011-11-22 13:18: >> >>> On 11/22/2011 6:09 AM, Arno Welzel wrote: >>>> Jerry Stuckle, 2011-11-21 18:46: >>>> >>>>> On 11/21/2011 9:31 AM, Arno Welzel wrote: >>>>>> Jerry Stuckle, 2011-11-21 15:13: >>>>>> >>>>>>> On 11/21/2011 9:07 AM, Arno Welzel wrote: >>>>>>>> DavidB, 2011-11-19 23:49: >>>>>>>> >>>>>>>>> Is there a way to model a session handler to auto logout after >>>>>>>>> a specified >>>>>>>>> period of time without refreshing the page? Something similar >>>>>>>>> to a bank >>>>>>>>> website that auto logs me out and redirects me to another page. >>>>>>>> >>>>>>>> If you want to force the client to redirect the user to another >>>>>>>> page as >>>>>>>> soon as the session on the *server* times out you must do >>>>>>>> periodically >>>>>>>> checks on the client e.g. using AJAX. >>>>>>>> >>>>>>>> >>>>>>> >>>>>>> Which is not what the op wants. But both Denis and myself already >>>>>>> pointed this out two days ago. What's your point? >>>>>> >>>>>> Using AJAX is not "refreshing the page". You just said "needs a >>>>>> request" >>>>>> and AJAX is a way to do a request. >>>>> >>>>> It is a way which will NOT work. >>>> >>>> Why? >>> >>> Because the AJAX call will reset the session timer, so the session will >>> never time out. >> >> And where did i say that the AJAX call should be *before* the session >> times out? >> > > Backpeddling, huh? No. You just don't understand it. >> And even if it is implemented this way - why should it not be possible >> to implement a server side script which responds to the AJAX calls and >> checks the existing session without resetting the session timeout? >> > > Backpeddling, huh? Nope. >> Hint: It is also possible to implement a session handling on your own. >> > > Yup, not easy to do, though. Recording a timestamp and checking if the time of the last request by the user (and not only the "check if session is still valid" request) is not older than x minutes is "not easy"? [...] >>> And I did not say "refresh the page". I said "needs a request". I >>> didn't say what KIND of request. >> >> So using AJAX to send a request is fine ;-) > > ROFLMAO! No, I didn't say AJAX was OK. > > Wise up. You were wrong, but refuse to admit it. Nope. You just don't understand it. -- Arno Welzel http://arnowelzel.de http://de-rec-fahrrad.de