Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > comp.lang.php > #3829 > unrolled thread
| Started by | DavidB <davidbrotman2768@gmail.com> |
|---|---|
| First post | 2011-11-19 14:49 -0800 |
| Last post | 2011-11-21 16:06 +0100 |
| Articles | 20 on this page of 33 — 6 participants |
Back to article view | Back to comp.lang.php
session handler auto log out DavidB <davidbrotman2768@gmail.com> - 2011-11-19 14:49 -0800
Re: session handler auto log out Jerry Stuckle <jstucklex@attglobal.net> - 2011-11-19 18:29 -0500
Re: session handler auto log out Denis McMahon <denismfmcmahon@gmail.com> - 2011-11-20 00:11 +0000
Re: session handler auto log out Arno Welzel <usenet@arnowelzel.de> - 2011-11-21 15:07 +0100
Re: session handler auto log out Jerry Stuckle <jstucklex@attglobal.net> - 2011-11-21 09:13 -0500
Re: session handler auto log out Arno Welzel <usenet@arnowelzel.de> - 2011-11-21 15:31 +0100
Re: session handler auto log out Jerry Stuckle <jstucklex@attglobal.net> - 2011-11-21 12:46 -0500
Re: session handler auto log out Arno Welzel <usenet@arnowelzel.de> - 2011-11-22 12:09 +0100
Re: session handler auto log out The Natural Philosopher <tnp@invalid.invalid> - 2011-11-22 11:18 +0000
Re: session handler auto log out Jerry Stuckle <jstucklex@attglobal.net> - 2011-11-22 07:20 -0500
Re: session handler auto log out Denis McMahon <denismfmcmahon@gmail.com> - 2011-11-22 13:29 +0000
Re: session handler auto log out Jerry Stuckle <jstucklex@attglobal.net> - 2011-11-22 07:18 -0500
Re: session handler auto log out Arno Welzel <usenet@arnowelzel.de> - 2011-11-22 16:55 +0100
Re: session handler auto log out Jerry Stuckle <jstucklex@attglobal.net> - 2011-11-22 13:18 -0500
Re: session handler auto log out Arno Welzel <usenet@arnowelzel.de> - 2011-11-23 10:17 +0100
Re: session handler auto log out Jerry Stuckle <jstucklex@attglobal.net> - 2011-11-23 06:12 -0500
Re: session handler auto log out Arno Welzel <usenet@arnowelzel.de> - 2011-11-23 16:04 +0100
Re: session handler auto log out Jerry Stuckle <jstucklex@attglobal.net> - 2011-11-23 10:39 -0500
Re: session handler auto log out Denis McMahon <denismfmcmahon@gmail.com> - 2011-11-23 18:58 +0000
Re: session handler auto log out Arno Welzel <usenet@arnowelzel.de> - 2011-11-23 20:42 +0100
Re: session handler auto log out Denis McMahon <denismfmcmahon@gmail.com> - 2011-11-23 23:07 +0000
Re: session handler auto log out Jerry Stuckle <jstucklex@attglobal.net> - 2011-11-23 23:57 -0500
Re: session handler auto log out Arno Welzel <usenet@arnowelzel.de> - 2011-11-24 09:53 +0100
Re: session handler auto log out Arno Welzel <usenet@arnowelzel.de> - 2011-11-24 11:19 +0100
Re: session handler auto log out Arno Welzel <usenet@arnowelzel.de> - 2011-11-24 09:47 +0100
Re: session handler auto log out Denis McMahon <denismfmcmahon@gmail.com> - 2011-11-23 02:09 +0000
Re: session handler auto log out Arno Welzel <usenet@arnowelzel.de> - 2011-11-23 10:22 +0100
Re: session handler auto log out Erwin Moller <Since_humans_read_this_I_am_spammed_too_much@spamyourself.com> - 2011-11-23 10:55 +0100
Re: session handler auto log out Denis McMahon <denismfmcmahon@gmail.com> - 2011-11-23 18:53 +0000
Re: session handler auto log out Erwin Moller <Since_humans_read_this_I_am_spammed_too_much@spamyourself.com> - 2011-11-25 10:40 +0100
Re: session handler auto log out Denis McMahon <denismfmcmahon@gmail.com> - 2011-11-26 18:36 +0000
Re: session handler auto log out Erwin Moller <Since_humans_read_this_I_am_spammed_too_much@spamyourself.com> - 2011-11-21 15:41 +0100
Re: session handler auto log out Arno Welzel <usenet@arnowelzel.de> - 2011-11-21 16:06 +0100
Page 1 of 2 [1] 2 Next page →
| From | DavidB <davidbrotman2768@gmail.com> |
|---|---|
| Date | 2011-11-19 14:49 -0800 |
| Subject | session handler auto log out |
| Message-ID | <11984037.1120.1321742991368.JavaMail.geo-discussion-forums@prlm15> |
Hi everyone: Is there a way to model a session handler to auto logout after a specified period of time without refreshing the page? Something similar to a bank website that auto logs me out and redirects me to another page.
[toc] | [next] | [standalone]
| From | Jerry Stuckle <jstucklex@attglobal.net> |
|---|---|
| Date | 2011-11-19 18:29 -0500 |
| Message-ID | <ja9e51$v91$1@dont-email.me> |
| In reply to | #3829 |
On 11/19/2011 5:49 PM, DavidB wrote: > Hi everyone: > > Is there a way to model a session handler to auto logout after a specified period of time without refreshing the page? Something similar to a bank website that auto logs me out and redirects me to another page. HTTP is a request/response protocol. While you can set a session timeout value on the server, you can't force the client to a different page from the server. It requires a request from the client. -- ================== Remove the "x" from my email address Jerry Stuckle JDS Computer Training Corp. jstucklex@attglobal.net ==================
[toc] | [prev] | [next] | [standalone]
| From | Denis McMahon <denismfmcmahon@gmail.com> |
|---|---|
| Date | 2011-11-20 00:11 +0000 |
| Message-ID | <4ec845c6$0$28568$a8266bb1@newsreader.readnews.com> |
| In reply to | #3829 |
On Sat, 19 Nov 2011 14:49:51 -0800, DavidB wrote: > Is there a way to model a session handler to auto logout after a > specified period of time without refreshing the page? Something similar > to a bank website that auto logs me out and redirects me to another > page. Yes, but not in the server php. All you can do in the server php is catch an invalid / unset / expired session cookie, assume it related to an expired session, and do the redirect when the user tries to reuse the expired session. On the client side, you can set timeouts in javascript, which is I would presume how banks implement such things, but I've never tried doing it myself. Perhaps people on comp.lang.javascript could offer suggestions. Rgds Denis McMahon
[toc] | [prev] | [next] | [standalone]
| From | Arno Welzel <usenet@arnowelzel.de> |
|---|---|
| Date | 2011-11-21 15:07 +0100 |
| Message-ID | <4ECA5B14.5020200@arnowelzel.de> |
| In reply to | #3829 |
DavidB, 2011-11-19 23:49: > Is there a way to model a session handler to auto logout after a specified > period of time without refreshing the page? Something similar to a bank > website that auto logs me out and redirects me to another page. If you want to force the client to redirect the user to another page as soon as the session on the *server* times out you must do periodically checks on the client e.g. using AJAX. -- Arno Welzel http://arnowelzel.de http://de-rec-fahrrad.de
[toc] | [prev] | [next] | [standalone]
| From | Jerry Stuckle <jstucklex@attglobal.net> |
|---|---|
| Date | 2011-11-21 09:13 -0500 |
| Message-ID | <jadmbd$uhj$2@dont-email.me> |
| In reply to | #3838 |
On 11/21/2011 9:07 AM, Arno Welzel wrote: > DavidB, 2011-11-19 23:49: > >> Is there a way to model a session handler to auto logout after a specified >> period of time without refreshing the page? Something similar to a bank >> website that auto logs me out and redirects me to another page. > > If you want to force the client to redirect the user to another page as > soon as the session on the *server* times out you must do periodically > checks on the client e.g. using AJAX. > > Which is not what the op wants. But both Denis and myself already pointed this out two days ago. What's your point? -- ================== Remove the "x" from my email address Jerry Stuckle JDS Computer Training Corp. jstucklex@attglobal.net ==================
[toc] | [prev] | [next] | [standalone]
| From | Arno Welzel <usenet@arnowelzel.de> |
|---|---|
| Date | 2011-11-21 15:31 +0100 |
| Message-ID | <4ECA60DE.6070301@arnowelzel.de> |
| In reply to | #3840 |
Jerry Stuckle, 2011-11-21 15:13: > On 11/21/2011 9:07 AM, Arno Welzel wrote: >> DavidB, 2011-11-19 23:49: >> >>> Is there a way to model a session handler to auto logout after a specified >>> period of time without refreshing the page? Something similar to a bank >>> website that auto logs me out and redirects me to another page. >> >> If you want to force the client to redirect the user to another page as >> soon as the session on the *server* times out you must do periodically >> checks on the client e.g. using AJAX. >> >> > > Which is not what the op wants. But both Denis and myself already > pointed this out two days ago. What's your point? Using AJAX is not "refreshing the page". You just said "needs a request" and AJAX is a way to do a request. -- Arno Welzel http://arnowelzel.de http://de-rec-fahrrad.de
[toc] | [prev] | [next] | [standalone]
| From | Jerry Stuckle <jstucklex@attglobal.net> |
|---|---|
| Date | 2011-11-21 12:46 -0500 |
| Message-ID | <jae2pp$ptj$1@dont-email.me> |
| In reply to | #3841 |
On 11/21/2011 9:31 AM, Arno Welzel wrote: > Jerry Stuckle, 2011-11-21 15:13: > >> On 11/21/2011 9:07 AM, Arno Welzel wrote: >>> DavidB, 2011-11-19 23:49: >>> >>>> Is there a way to model a session handler to auto logout after a specified >>>> period of time without refreshing the page? Something similar to a bank >>>> website that auto logs me out and redirects me to another page. >>> >>> If you want to force the client to redirect the user to another page as >>> soon as the session on the *server* times out you must do periodically >>> checks on the client e.g. using AJAX. >>> >>> >> >> Which is not what the op wants. But both Denis and myself already >> pointed this out two days ago. What's your point? > > Using AJAX is not "refreshing the page". You just said "needs a request" > and AJAX is a way to do a request. > > It is a way which will NOT work. -- ================== Remove the "x" from my email address Jerry Stuckle JDS Computer Training Corp. jstucklex@attglobal.net ==================
[toc] | [prev] | [next] | [standalone]
| From | Arno Welzel <usenet@arnowelzel.de> |
|---|---|
| Date | 2011-11-22 12:09 +0100 |
| Message-ID | <4ECB82D1.2000902@arnowelzel.de> |
| In reply to | #3846 |
Jerry Stuckle, 2011-11-21 18:46: > On 11/21/2011 9:31 AM, Arno Welzel wrote: >> Jerry Stuckle, 2011-11-21 15:13: >> >>> On 11/21/2011 9:07 AM, Arno Welzel wrote: >>>> DavidB, 2011-11-19 23:49: >>>> >>>>> Is there a way to model a session handler to auto logout after a specified >>>>> period of time without refreshing the page? Something similar to a bank >>>>> website that auto logs me out and redirects me to another page. >>>> >>>> If you want to force the client to redirect the user to another page as >>>> soon as the session on the *server* times out you must do periodically >>>> checks on the client e.g. using AJAX. >>>> >>>> >>> >>> Which is not what the op wants. But both Denis and myself already >>> pointed this out two days ago. What's your point? >> >> Using AJAX is not "refreshing the page". You just said "needs a request" >> and AJAX is a way to do a request. > > It is a way which will NOT work. Why? -- Arno Welzel http://arnowelzel.de http://de-rec-fahrrad.de
[toc] | [prev] | [next] | [standalone]
| From | The Natural Philosopher <tnp@invalid.invalid> |
|---|---|
| Date | 2011-11-22 11:18 +0000 |
| Message-ID | <jag0el$36a$2@news.albasani.net> |
| In reply to | #3853 |
Arno Welzel wrote: > Jerry Stuckle, 2011-11-21 18:46: > >> On 11/21/2011 9:31 AM, Arno Welzel wrote: >>> Jerry Stuckle, 2011-11-21 15:13: >>> >>>> On 11/21/2011 9:07 AM, Arno Welzel wrote: >>>>> DavidB, 2011-11-19 23:49: >>>>> >>>>>> Is there a way to model a session handler to auto logout after a specified >>>>>> period of time without refreshing the page? Something similar to a bank >>>>>> website that auto logs me out and redirects me to another page. >>>>> If you want to force the client to redirect the user to another page as >>>>> soon as the session on the *server* times out you must do periodically >>>>> checks on the client e.g. using AJAX. >>>>> >>>>> >>>> Which is not what the op wants. But both Denis and myself already >>>> pointed this out two days ago. What's your point? >>> Using AJAX is not "refreshing the page". You just said "needs a request" >>> and AJAX is a way to do a request. >> It is a way which will NOT work. > > Why? > > Because Jerry Says So, And Jerry is Never Wrong. >
[toc] | [prev] | [next] | [standalone]
| From | Jerry Stuckle <jstucklex@attglobal.net> |
|---|---|
| Date | 2011-11-22 07:20 -0500 |
| Message-ID | <jag41o$5um$2@dont-email.me> |
| In reply to | #3854 |
On 11/22/2011 6:18 AM, The Natural Philosopher wrote: > Arno Welzel wrote: >> Jerry Stuckle, 2011-11-21 18:46: >> >>> On 11/21/2011 9:31 AM, Arno Welzel wrote: >>>> Jerry Stuckle, 2011-11-21 15:13: >>>> >>>>> On 11/21/2011 9:07 AM, Arno Welzel wrote: >>>>>> DavidB, 2011-11-19 23:49: >>>>>> >>>>>>> Is there a way to model a session handler to auto logout after a >>>>>>> specified >>>>>>> period of time without refreshing the page? Something similar to >>>>>>> a bank >>>>>>> website that auto logs me out and redirects me to another page. >>>>>> If you want to force the client to redirect the user to another >>>>>> page as >>>>>> soon as the session on the *server* times out you must do >>>>>> periodically >>>>>> checks on the client e.g. using AJAX. >>>>>> >>>>>> >>>>> Which is not what the op wants. But both Denis and myself already >>>>> pointed this out two days ago. What's your point? >>>> Using AJAX is not "refreshing the page". You just said "needs a >>>> request" >>>> and AJAX is a way to do a request. >>> It is a way which will NOT work. >> >> Why? >> >> > > Because Jerry Says So, And Jerry is Never Wrong. > >> There's TNP again. I knew the troll would show up sooner or later. Lost another job digging ditches because you couldn't figure out which end of the shovel to use? -- ================== Remove the "x" from my email address Jerry Stuckle JDS Computer Training Corp. jstucklex@attglobal.net ==================
[toc] | [prev] | [next] | [standalone]
| From | Denis McMahon <denismfmcmahon@gmail.com> |
|---|---|
| Date | 2011-11-22 13:29 +0000 |
| Message-ID | <4ecba3ac$0$28579$a8266bb1@newsreader.readnews.com> |
| In reply to | #3861 |
On Tue, 22 Nov 2011 07:20:01 -0500, Jerry Stuckle wrote: > Lost another job digging ditches because you couldn't figure out which > end of the shovel to use? The end that creates the greater hole to dig himself into of course. Rgds Denis McMahon
[toc] | [prev] | [next] | [standalone]
| From | Jerry Stuckle <jstucklex@attglobal.net> |
|---|---|
| Date | 2011-11-22 07:18 -0500 |
| Message-ID | <jag3vp$5um$1@dont-email.me> |
| In reply to | #3853 |
On 11/22/2011 6:09 AM, Arno Welzel wrote: > Jerry Stuckle, 2011-11-21 18:46: > >> On 11/21/2011 9:31 AM, Arno Welzel wrote: >>> Jerry Stuckle, 2011-11-21 15:13: >>> >>>> On 11/21/2011 9:07 AM, Arno Welzel wrote: >>>>> DavidB, 2011-11-19 23:49: >>>>> >>>>>> Is there a way to model a session handler to auto logout after a specified >>>>>> period of time without refreshing the page? Something similar to a bank >>>>>> website that auto logs me out and redirects me to another page. >>>>> >>>>> If you want to force the client to redirect the user to another page as >>>>> soon as the session on the *server* times out you must do periodically >>>>> checks on the client e.g. using AJAX. >>>>> >>>>> >>>> >>>> Which is not what the op wants. But both Denis and myself already >>>> pointed this out two days ago. What's your point? >>> >>> Using AJAX is not "refreshing the page". You just said "needs a request" >>> and AJAX is a way to do a request. >> >> It is a way which will NOT work. > > Why? > > > Because the AJAX call will reset the session timer, so the session will never time out. It also requires javascript running on the client, which may or may not be the case. And I did not say "refresh the page". I said "needs a request". I didn't say what KIND of request. -- g ================== Remove the "x" from my email address Jerry Stuckle JDS Computer Training Corp. jstucklex@attglobal.net ==================
[toc] | [prev] | [next] | [standalone]
| From | Arno Welzel <usenet@arnowelzel.de> |
|---|---|
| Date | 2011-11-22 16:55 +0100 |
| Message-ID | <4ECBC5FC.4050306@arnowelzel.de> |
| In reply to | #3860 |
Jerry Stuckle, 2011-11-22 13:18: > On 11/22/2011 6:09 AM, Arno Welzel wrote: >> Jerry Stuckle, 2011-11-21 18:46: >> >>> On 11/21/2011 9:31 AM, Arno Welzel wrote: >>>> Jerry Stuckle, 2011-11-21 15:13: >>>> >>>>> On 11/21/2011 9:07 AM, Arno Welzel wrote: >>>>>> DavidB, 2011-11-19 23:49: >>>>>> >>>>>>> Is there a way to model a session handler to auto logout after a specified >>>>>>> period of time without refreshing the page? Something similar to a bank >>>>>>> website that auto logs me out and redirects me to another page. >>>>>> >>>>>> If you want to force the client to redirect the user to another page as >>>>>> soon as the session on the *server* times out you must do periodically >>>>>> checks on the client e.g. using AJAX. >>>>>> >>>>>> >>>>> >>>>> Which is not what the op wants. But both Denis and myself already >>>>> pointed this out two days ago. What's your point? >>>> >>>> Using AJAX is not "refreshing the page". You just said "needs a request" >>>> and AJAX is a way to do a request. >>> >>> It is a way which will NOT work. >> >> Why? > > Because the AJAX call will reset the session timer, so the session will > never time out. And where did i say that the AJAX call should be *before* the session times out? And even if it is implemented this way - why should it not be possible to implement a server side script which responds to the AJAX calls and checks the existing session without resetting the session timeout? Hint: It is also possible to implement a session handling on your own. > It also requires javascript running on the client, which may or may not > be the case. In this case the automatic redirect will not occur, but the session will time out anyway. > And I did not say "refresh the page". I said "needs a request". I > didn't say what KIND of request. So using AJAX to send a request is fine ;-) -- Arno Welzel http://arnowelzel.de http://de-rec-fahrrad.de
[toc] | [prev] | [next] | [standalone]
| From | Jerry Stuckle <jstucklex@attglobal.net> |
|---|---|
| Date | 2011-11-22 13:18 -0500 |
| Message-ID | <jagp2k$dka$1@dont-email.me> |
| In reply to | #3867 |
On 11/22/2011 10:55 AM, Arno Welzel wrote: > Jerry Stuckle, 2011-11-22 13:18: > >> On 11/22/2011 6:09 AM, Arno Welzel wrote: >>> Jerry Stuckle, 2011-11-21 18:46: >>> >>>> On 11/21/2011 9:31 AM, Arno Welzel wrote: >>>>> Jerry Stuckle, 2011-11-21 15:13: >>>>> >>>>>> On 11/21/2011 9:07 AM, Arno Welzel wrote: >>>>>>> DavidB, 2011-11-19 23:49: >>>>>>> >>>>>>>> Is there a way to model a session handler to auto logout after a specified >>>>>>>> period of time without refreshing the page? Something similar to a bank >>>>>>>> website that auto logs me out and redirects me to another page. >>>>>>> >>>>>>> If you want to force the client to redirect the user to another page as >>>>>>> soon as the session on the *server* times out you must do periodically >>>>>>> checks on the client e.g. using AJAX. >>>>>>> >>>>>>> >>>>>> >>>>>> Which is not what the op wants. But both Denis and myself already >>>>>> pointed this out two days ago. What's your point? >>>>> >>>>> Using AJAX is not "refreshing the page". You just said "needs a request" >>>>> and AJAX is a way to do a request. >>>> >>>> It is a way which will NOT work. >>> >>> Why? >> >> Because the AJAX call will reset the session timer, so the session will >> never time out. > > And where did i say that the AJAX call should be *before* the session > times out? > Backpeddling, huh? > And even if it is implemented this way - why should it not be possible > to implement a server side script which responds to the AJAX calls and > checks the existing session without resetting the session timeout? > Backpeddling, huh? > Hint: It is also possible to implement a session handling on your own. > Yup, not easy to do, though. >> It also requires javascript running on the client, which may or may not >> be the case. > > In this case the automatic redirect will not occur, but the session will > time out anyway. > Sure. As it will if you don't use AJAX at all. >> And I did not say "refresh the page". I said "needs a request". I >> didn't say what KIND of request. > > So using AJAX to send a request is fine ;-) > > > ROFLMAO! No, I didn't say AJAX was OK. Wise up. You were wrong, but refuse to admit it. -- ================== Remove the "x" from my email address Jerry Stuckle JDS Computer Training Corp. jstucklex@attglobal.net ==================
[toc] | [prev] | [next] | [standalone]
| From | Arno Welzel <usenet@arnowelzel.de> |
|---|---|
| Date | 2011-11-23 10:17 +0100 |
| Message-ID | <4ECCBA39.9070501@arnowelzel.de> |
| In reply to | #3877 |
Jerry Stuckle, 2011-11-22 19:18: > On 11/22/2011 10:55 AM, Arno Welzel wrote: >> Jerry Stuckle, 2011-11-22 13:18: >> >>> On 11/22/2011 6:09 AM, Arno Welzel wrote: >>>> Jerry Stuckle, 2011-11-21 18:46: >>>> >>>>> On 11/21/2011 9:31 AM, Arno Welzel wrote: >>>>>> Jerry Stuckle, 2011-11-21 15:13: >>>>>> >>>>>>> On 11/21/2011 9:07 AM, Arno Welzel wrote: >>>>>>>> DavidB, 2011-11-19 23:49: >>>>>>>> >>>>>>>>> Is there a way to model a session handler to auto logout after >>>>>>>>> a specified >>>>>>>>> period of time without refreshing the page? Something similar >>>>>>>>> to a bank >>>>>>>>> website that auto logs me out and redirects me to another page. >>>>>>>> >>>>>>>> If you want to force the client to redirect the user to another >>>>>>>> page as >>>>>>>> soon as the session on the *server* times out you must do >>>>>>>> periodically >>>>>>>> checks on the client e.g. using AJAX. >>>>>>>> >>>>>>>> >>>>>>> >>>>>>> Which is not what the op wants. But both Denis and myself already >>>>>>> pointed this out two days ago. What's your point? >>>>>> >>>>>> Using AJAX is not "refreshing the page". You just said "needs a >>>>>> request" >>>>>> and AJAX is a way to do a request. >>>>> >>>>> It is a way which will NOT work. >>>> >>>> Why? >>> >>> Because the AJAX call will reset the session timer, so the session will >>> never time out. >> >> And where did i say that the AJAX call should be *before* the session >> times out? >> > > Backpeddling, huh? No. You just don't understand it. >> And even if it is implemented this way - why should it not be possible >> to implement a server side script which responds to the AJAX calls and >> checks the existing session without resetting the session timeout? >> > > Backpeddling, huh? Nope. >> Hint: It is also possible to implement a session handling on your own. >> > > Yup, not easy to do, though. Recording a timestamp and checking if the time of the last request by the user (and not only the "check if session is still valid" request) is not older than x minutes is "not easy"? [...] >>> And I did not say "refresh the page". I said "needs a request". I >>> didn't say what KIND of request. >> >> So using AJAX to send a request is fine ;-) > > ROFLMAO! No, I didn't say AJAX was OK. > > Wise up. You were wrong, but refuse to admit it. Nope. You just don't understand it. -- Arno Welzel http://arnowelzel.de http://de-rec-fahrrad.de
[toc] | [prev] | [next] | [standalone]
| From | Jerry Stuckle <jstucklex@attglobal.net> |
|---|---|
| Date | 2011-11-23 06:12 -0500 |
| Message-ID | <jaikfl$mt9$1@dont-email.me> |
| In reply to | #3884 |
On 11/23/2011 4:17 AM, Arno Welzel wrote: > Jerry Stuckle, 2011-11-22 19:18: > >> On 11/22/2011 10:55 AM, Arno Welzel wrote: >>> Jerry Stuckle, 2011-11-22 13:18: >>> >>>> On 11/22/2011 6:09 AM, Arno Welzel wrote: >>>>> Jerry Stuckle, 2011-11-21 18:46: >>>>> >>>>>> On 11/21/2011 9:31 AM, Arno Welzel wrote: >>>>>>> Jerry Stuckle, 2011-11-21 15:13: >>>>>>> >>>>>>>> On 11/21/2011 9:07 AM, Arno Welzel wrote: >>>>>>>>> DavidB, 2011-11-19 23:49: >>>>>>>>> >>>>>>>>>> Is there a way to model a session handler to auto logout after >>>>>>>>>> a specified >>>>>>>>>> period of time without refreshing the page? Something similar >>>>>>>>>> to a bank >>>>>>>>>> website that auto logs me out and redirects me to another page. >>>>>>>>> >>>>>>>>> If you want to force the client to redirect the user to another >>>>>>>>> page as >>>>>>>>> soon as the session on the *server* times out you must do >>>>>>>>> periodically >>>>>>>>> checks on the client e.g. using AJAX. >>>>>>>>> >>>>>>>>> >>>>>>>> >>>>>>>> Which is not what the op wants. But both Denis and myself already >>>>>>>> pointed this out two days ago. What's your point? >>>>>>> >>>>>>> Using AJAX is not "refreshing the page". You just said "needs a >>>>>>> request" >>>>>>> and AJAX is a way to do a request. >>>>>> >>>>>> It is a way which will NOT work. >>>>> >>>>> Why? >>>> >>>> Because the AJAX call will reset the session timer, so the session will >>>> never time out. >>> >>> And where did i say that the AJAX call should be *before* the session >>> times out? >>> >> >> Backpeddling, huh? > > No. You just don't understand it. > I understand completely, backpeddler. >>> And even if it is implemented this way - why should it not be possible >>> to implement a server side script which responds to the AJAX calls and >>> checks the existing session without resetting the session timeout? >>> >> >> Backpeddling, huh? > > Nope. > Yep. >>> Hint: It is also possible to implement a session handling on your own. >>> >> >> Yup, not easy to do, though. > > Recording a timestamp and checking if the time of the last request by > the user (and not only the "check if session is still valid" request) is > not older than x minutes is "not easy"? > A lot more to it than that, if you actually understood session handling. > [...] >>>> And I did not say "refresh the page". I said "needs a request". I >>>> didn't say what KIND of request. >>> >>> So using AJAX to send a request is fine ;-) >> >> ROFLMAO! No, I didn't say AJAX was OK. >> >> Wise up. You were wrong, but refuse to admit it. > > Nope. You just don't understand it. > > I understand completely, backpeddler. -- ================== Remove the "x" from my email address Jerry Stuckle JDS Computer Training Corp. jstucklex@attglobal.net ==================
[toc] | [prev] | [next] | [standalone]
| From | Arno Welzel <usenet@arnowelzel.de> |
|---|---|
| Date | 2011-11-23 16:04 +0100 |
| Message-ID | <4ECD0B7F.6000803@arnowelzel.de> |
| In reply to | #3888 |
Jerry Stuckle, 2011-11-23 12:12: > On 11/23/2011 4:17 AM, Arno Welzel wrote: >> Jerry Stuckle, 2011-11-22 19:18: >> >>> On 11/22/2011 10:55 AM, Arno Welzel wrote: >>>> Jerry Stuckle, 2011-11-22 13:18: >>>> >>>>> On 11/22/2011 6:09 AM, Arno Welzel wrote: >>>>>> Jerry Stuckle, 2011-11-21 18:46: >>>>>> >>>>>>> On 11/21/2011 9:31 AM, Arno Welzel wrote: >>>>>>>> Jerry Stuckle, 2011-11-21 15:13: >>>>>>>> >>>>>>>>> On 11/21/2011 9:07 AM, Arno Welzel wrote: >>>>>>>>>> DavidB, 2011-11-19 23:49: >>>>>>>>>> >>>>>>>>>>> Is there a way to model a session handler to auto logout after >>>>>>>>>>> a specified >>>>>>>>>>> period of time without refreshing the page? Something similar >>>>>>>>>>> to a bank >>>>>>>>>>> website that auto logs me out and redirects me to another page. >>>>>>>>>> >>>>>>>>>> If you want to force the client to redirect the user to another >>>>>>>>>> page as >>>>>>>>>> soon as the session on the *server* times out you must do >>>>>>>>>> periodically >>>>>>>>>> checks on the client e.g. using AJAX. >>>>>>>>>> >>>>>>>>>> >>>>>>>>> >>>>>>>>> Which is not what the op wants. But both Denis and myself already >>>>>>>>> pointed this out two days ago. What's your point? >>>>>>>> >>>>>>>> Using AJAX is not "refreshing the page". You just said "needs a >>>>>>>> request" >>>>>>>> and AJAX is a way to do a request. >>>>>>> >>>>>>> It is a way which will NOT work. >>>>>> >>>>>> Why? >>>>> >>>>> Because the AJAX call will reset the session timer, so the session will >>>>> never time out. >>>> >>>> And where did i say that the AJAX call should be *before* the session >>>> times out? >>>> >>> >>> Backpeddling, huh? >> >> No. You just don't understand it. >> > > I understand completely, backpeddler. > >>>> And even if it is implemented this way - why should it not be possible >>>> to implement a server side script which responds to the AJAX calls and >>>> checks the existing session without resetting the session timeout? >>>> >>> >>> Backpeddling, huh? >> >> Nope. >> > > Yep. You still don't get it. >>>> Hint: It is also possible to implement a session handling on your own. >>>> >>> >>> Yup, not easy to do, though. >> >> Recording a timestamp and checking if the time of the last request by >> the user (and not only the "check if session is still valid" request) is >> not older than x minutes is "not easy"? >> > > A lot more to it than that, if you actually understood session handling. I do. >> [...] >>>>> And I did not say "refresh the page". I said "needs a request". I >>>>> didn't say what KIND of request. >>>> >>>> So using AJAX to send a request is fine ;-) >>> >>> ROFLMAO! No, I didn't say AJAX was OK. >>> >>> Wise up. You were wrong, but refuse to admit it. >> >> Nope. You just don't understand it. > > I understand completely, backpeddler. No you don't. You said: "While you can set a session timeout value on the server, you can't force the client to a different page from the server. It requires a request from the client." You don't understand because you assume that any request will *always* reset the session timeout and you assume that relying on PHPs own session handling is the only way to go. -- Arno Welzel http://arnowelzel.de http://de-rec-fahrrad.de
[toc] | [prev] | [next] | [standalone]
| From | Jerry Stuckle <jstucklex@attglobal.net> |
|---|---|
| Date | 2011-11-23 10:39 -0500 |
| Message-ID | <jaj43a$m1j$1@dont-email.me> |
| In reply to | #3891 |
On 11/23/2011 10:04 AM, Arno Welzel wrote: > Jerry Stuckle, 2011-11-23 12:12: > >> On 11/23/2011 4:17 AM, Arno Welzel wrote: >>> Jerry Stuckle, 2011-11-22 19:18: >>> >>>> On 11/22/2011 10:55 AM, Arno Welzel wrote: >>>>> Jerry Stuckle, 2011-11-22 13:18: >>>>> >>>>>> On 11/22/2011 6:09 AM, Arno Welzel wrote: >>>>>>> Jerry Stuckle, 2011-11-21 18:46: >>>>>>> >>>>>>>> On 11/21/2011 9:31 AM, Arno Welzel wrote: >>>>>>>>> Jerry Stuckle, 2011-11-21 15:13: >>>>>>>>> >>>>>>>>>> On 11/21/2011 9:07 AM, Arno Welzel wrote: >>>>>>>>>>> DavidB, 2011-11-19 23:49: >>>>>>>>>>> >>>>>>>>>>>> Is there a way to model a session handler to auto logout after >>>>>>>>>>>> a specified >>>>>>>>>>>> period of time without refreshing the page? Something similar >>>>>>>>>>>> to a bank >>>>>>>>>>>> website that auto logs me out and redirects me to another page. >>>>>>>>>>> >>>>>>>>>>> If you want to force the client to redirect the user to another >>>>>>>>>>> page as >>>>>>>>>>> soon as the session on the *server* times out you must do >>>>>>>>>>> periodically >>>>>>>>>>> checks on the client e.g. using AJAX. >>>>>>>>>>> >>>>>>>>>>> >>>>>>>>>> >>>>>>>>>> Which is not what the op wants. But both Denis and myself already >>>>>>>>>> pointed this out two days ago. What's your point? >>>>>>>>> >>>>>>>>> Using AJAX is not "refreshing the page". You just said "needs a >>>>>>>>> request" >>>>>>>>> and AJAX is a way to do a request. >>>>>>>> >>>>>>>> It is a way which will NOT work. >>>>>>> >>>>>>> Why? >>>>>> >>>>>> Because the AJAX call will reset the session timer, so the session will >>>>>> never time out. >>>>> >>>>> And where did i say that the AJAX call should be *before* the session >>>>> times out? >>>>> >>>> >>>> Backpeddling, huh? >>> >>> No. You just don't understand it. >>> >> >> I understand completely, backpeddler. >> >>>>> And even if it is implemented this way - why should it not be possible >>>>> to implement a server side script which responds to the AJAX calls and >>>>> checks the existing session without resetting the session timeout? >>>>> >>>> >>>> Backpeddling, huh? >>> >>> Nope. >>> >> >> Yep. > > You still don't get it. > >>>>> Hint: It is also possible to implement a session handling on your own. >>>>> >>>> >>>> Yup, not easy to do, though. >>> >>> Recording a timestamp and checking if the time of the last request by >>> the user (and not only the "check if session is still valid" request) is >>> not older than x minutes is "not easy"? >>> >> >> A lot more to it than that, if you actually understood session handling. > > I do. > >>> [...] >>>>>> And I did not say "refresh the page". I said "needs a request". I >>>>>> didn't say what KIND of request. >>>>> >>>>> So using AJAX to send a request is fine ;-) >>>> >>>> ROFLMAO! No, I didn't say AJAX was OK. >>>> >>>> Wise up. You were wrong, but refuse to admit it. >>> >>> Nope. You just don't understand it. >> >> I understand completely, backpeddler. > > No you don't. You said: > > "While you can set a session timeout value on the server, you can't > force the client to a different page from the server. It requires a > request from the client." > > You don't understand because you assume that any request will *always* > reset the session timeout and you assume that relying on PHPs own > session handling is the only way to go. > > No, but I also know that any request which does not reset the timeout does not cause a redirect. We are talking PHP sessions here, not something you've cobbled up on the side. And that's how PHP sessions work. -- ================== Remove the "x" from my email address Jerry Stuckle JDS Computer Training Corp. jstucklex@attglobal.net ==================
[toc] | [prev] | [next] | [standalone]
| From | Denis McMahon <denismfmcmahon@gmail.com> |
|---|---|
| Date | 2011-11-23 18:58 +0000 |
| Message-ID | <4ecd4241$0$28492$a8266bb1@newsreader.readnews.com> |
| In reply to | #3884 |
On Wed, 23 Nov 2011 10:17:45 +0100, Arno Welzel wrote: >>> Hint: It is also possible to implement a session handling on your own. >> Yup, not easy to do, though. > Recording a timestamp and checking if the time of the last request by > the user (and not only the "check if session is still valid" request) is > not older than x minutes is "not easy"? and the session variables? Rgds Denis McMahon
[toc] | [prev] | [next] | [standalone]
| From | Arno Welzel <usenet@arnowelzel.de> |
|---|---|
| Date | 2011-11-23 20:42 +0100 |
| Message-ID | <4ECD4CB0.5020903@arnowelzel.de> |
| In reply to | #3896 |
Denis McMahon, 2011-11-23 19:58: > On Wed, 23 Nov 2011 10:17:45 +0100, Arno Welzel wrote: > >>>> Hint: It is also possible to implement a session handling on your own. > >>> Yup, not easy to do, though. > >> Recording a timestamp and checking if the time of the last request by >> the user (and not only the "check if session is still valid" request) is >> not older than x minutes is "not easy"? > > and the session variables? They get lost, as soon as the PHP session times out of course - but by doing periodically request using JavaScript this will not happen, so one has to implement additional logic to maintain your application specific session timeout and to distinguish between the periodically session checks via JavaScript and "real" requests caused by user interaction. In case JavaScript is not available, the session will just time out, any session variable will be lost and usually the redirection to a "session timed out" page will be done using the referrer which indicates the previous page was one which is only accessible for logged in users. If there is even no referrer you can not distinguish between a session timeout or a new session and you have to redirect to a general login page, maybe with an additional explanation like "maybe your session timed out because we did not receive any request for more than 5 minutes" or similar. -- Arno Welzel http://arnowelzel.de http://de-rec-fahrrad.de
[toc] | [prev] | [next] | [standalone]
Page 1 of 2 [1] 2 Next page →
Back to top | Article view | comp.lang.php
csiph-web