Path: csiph.com!x330-a1.tempe.blueboxinc.net!usenet.pasdenom.info!aioe.org!eternal-september.org!feeder.eternal-september.org!.POSTED!not-for-mail From: Arno Welzel Newsgroups: comp.lang.php Subject: Re: session handler auto log out Date: Wed, 23 Nov 2011 10:22:51 +0100 Organization: A noiseless patient Spider Lines: 36 Message-ID: <4ECCBB6B.9050507@arnowelzel.de> References: <11984037.1120.1321742991368.JavaMail.geo-discussion-forums@prlm15> <4ECA5B14.5020200@arnowelzel.de> <4ECA60DE.6070301@arnowelzel.de> <4ECB82D1.2000902@arnowelzel.de> <4ECBC5FC.4050306@arnowelzel.de> <4ecc55c3$0$28595$a8266bb1@newsreader.readnews.com> Mime-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 7bit Injection-Info: mx04.eternal-september.org; posting-host="dmYg0DIsuEi3Fj+mt8IKsg"; logging-data="21752"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX18WSmY43uzi8EdDFqF6L6sSGoSKi26Zs0E=" User-Agent: Mozilla/5.0 (Windows NT 5.1; rv:8.0) Gecko/20111105 Thunderbird/8.0 In-Reply-To: <4ecc55c3$0$28595$a8266bb1@newsreader.readnews.com> Cancel-Lock: sha1:fSG6WBSQG3n+ebtcLkYzCphx4AM= Xref: x330-a1.tempe.blueboxinc.net comp.lang.php:3885 Denis McMahon, 2011-11-23 03:09: > On Tue, 22 Nov 2011 16:55:40 +0100, Arno Welzel wrote: > >>> Because the AJAX call will reset the session timer, so the session will >>> never time out. >> >> And where did i say that the AJAX call should be *before* the session >> times out? > > If the ajax call is made after the session has timed out, then you're > back to the previously discussed situation where you get a request > without a valid current session ID and do with it as you wish. Which can be handled of course. > Any request, whether ajax initiated, a form submission, clicking a link, > grabbing an image etc will send the session cookie from the client to the > server if a session cookie is defined. > > If php code is invoked to handle the request and that code invokes the > session handler, then the session timer will be reset and an updated > session cookie reflecting the new timeout / expiry will be sent to the > client. > >> Hint: It is also possible to implement a session handling on your own. > > Then you need to go and write your own session handler. Have fun. Maybe you should have a look to DokukWikis session handling as an example. -- Arno Welzel http://arnowelzel.de http://de-rec-fahrrad.de