Path: csiph.com!x330-a1.tempe.blueboxinc.net!usenet.pasdenom.info!aioe.org!eternal-september.org!feeder.eternal-september.org!mx04.eternal-september.org!.POSTED!not-for-mail From: Arno Welzel Newsgroups: comp.lang.php Subject: Re: sessions timeout Date: Wed, 04 Jan 2012 09:20:53 +0100 Organization: A noiseless patient Spider Lines: 40 Message-ID: <4F040BE5.7000207@arnowelzel.de> References: <66b7g7lk434p6vk68429d8np5134jd52hd@4ax.com> Mime-Version: 1.0 Content-Type: text/plain; charset=ISO-8859-1 Content-Transfer-Encoding: 7bit Injection-Info: mx04.eternal-september.org; posting-host="Psb2+p0U7wkhKleuxO8/EQ"; logging-data="28778"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX18N+nFksrnf4AlbwhxLvzWy0VbWLm8V6xo=" User-Agent: Mozilla/5.0 (Windows NT 5.1; rv:9.0) Gecko/20111222 Thunderbird/9.0.1 In-Reply-To: <66b7g7lk434p6vk68429d8np5134jd52hd@4ax.com> Cancel-Lock: sha1:gfFNrFVeXMFmpjBJ8VSj6O9ir1o= Xref: x330-a1.tempe.blueboxinc.net comp.lang.php:4214 Michael Joel, 2012-01-04 02:42: > I am on a shared server so I have no control over the settings. > > Is there a way for me to set a "timeout" for sessions? Maybe using ini_set() to modify session.cookie_lifetime - but i'm not sure if this is possible. Another way would be to manage this "manually" - e.g. using the current time and the time of the last activity of the user: 1) When the session is created also store the current time as a session variable. 2) If there is already a session compare the current time with the time recorded in the session and then either destroy the session, if the time span is too long OR update the time in the session. > I am working on some scripts (logged in as a test user) and had been > away from it for a few hours. The tabs (this is Opera browser) were > closed, but not the browser. > > When I went back to the page it still had me logged in. Sure - the cookie is still there as long as the browser is running. > Obviously the server session cookies are set to clear when the browser > closes. > > Is there a way for me to have some control over this and set a time > limit so after a reasonable amount of time the session cookie clears? See above. -- Arno Welzel http://arnowelzel.de http://de-rec-fahrrad.de