Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > comp.lang.php > #3829 > unrolled thread

session handler auto log out

Started byDavidB <davidbrotman2768@gmail.com>
First post2011-11-19 14:49 -0800
Last post2011-11-21 16:06 +0100
Articles 20 on this page of 33 — 6 participants

Back to article view | Back to comp.lang.php


Contents

  session handler auto log out DavidB <davidbrotman2768@gmail.com> - 2011-11-19 14:49 -0800
    Re: session handler auto log out Jerry Stuckle <jstucklex@attglobal.net> - 2011-11-19 18:29 -0500
    Re: session handler auto log out Denis McMahon <denismfmcmahon@gmail.com> - 2011-11-20 00:11 +0000
    Re: session handler auto log out Arno Welzel <usenet@arnowelzel.de> - 2011-11-21 15:07 +0100
      Re: session handler auto log out Jerry Stuckle <jstucklex@attglobal.net> - 2011-11-21 09:13 -0500
        Re: session handler auto log out Arno Welzel <usenet@arnowelzel.de> - 2011-11-21 15:31 +0100
          Re: session handler auto log out Jerry Stuckle <jstucklex@attglobal.net> - 2011-11-21 12:46 -0500
            Re: session handler auto log out Arno Welzel <usenet@arnowelzel.de> - 2011-11-22 12:09 +0100
              Re: session handler auto log out The Natural Philosopher <tnp@invalid.invalid> - 2011-11-22 11:18 +0000
                Re: session handler auto log out Jerry Stuckle <jstucklex@attglobal.net> - 2011-11-22 07:20 -0500
                  Re: session handler auto log out Denis McMahon <denismfmcmahon@gmail.com> - 2011-11-22 13:29 +0000
              Re: session handler auto log out Jerry Stuckle <jstucklex@attglobal.net> - 2011-11-22 07:18 -0500
                Re: session handler auto log out Arno Welzel <usenet@arnowelzel.de> - 2011-11-22 16:55 +0100
                  Re: session handler auto log out Jerry Stuckle <jstucklex@attglobal.net> - 2011-11-22 13:18 -0500
                    Re: session handler auto log out Arno Welzel <usenet@arnowelzel.de> - 2011-11-23 10:17 +0100
                      Re: session handler auto log out Jerry Stuckle <jstucklex@attglobal.net> - 2011-11-23 06:12 -0500
                        Re: session handler auto log out Arno Welzel <usenet@arnowelzel.de> - 2011-11-23 16:04 +0100
                          Re: session handler auto log out Jerry Stuckle <jstucklex@attglobal.net> - 2011-11-23 10:39 -0500
                      Re: session handler auto log out Denis McMahon <denismfmcmahon@gmail.com> - 2011-11-23 18:58 +0000
                        Re: session handler auto log out Arno Welzel <usenet@arnowelzel.de> - 2011-11-23 20:42 +0100
                          Re: session handler auto log out Denis McMahon <denismfmcmahon@gmail.com> - 2011-11-23 23:07 +0000
                            Re: session handler auto log out Jerry Stuckle <jstucklex@attglobal.net> - 2011-11-23 23:57 -0500
                              Re: session handler auto log out Arno Welzel <usenet@arnowelzel.de> - 2011-11-24 09:53 +0100
                                Re: session handler auto log out Arno Welzel <usenet@arnowelzel.de> - 2011-11-24 11:19 +0100
                            Re: session handler auto log out Arno Welzel <usenet@arnowelzel.de> - 2011-11-24 09:47 +0100
                  Re: session handler auto log out Denis McMahon <denismfmcmahon@gmail.com> - 2011-11-23 02:09 +0000
                    Re: session handler auto log out Arno Welzel <usenet@arnowelzel.de> - 2011-11-23 10:22 +0100
                    Re: session handler auto log out Erwin Moller <Since_humans_read_this_I_am_spammed_too_much@spamyourself.com> - 2011-11-23 10:55 +0100
                      Re: session handler auto log out Denis McMahon <denismfmcmahon@gmail.com> - 2011-11-23 18:53 +0000
                        Re: session handler auto log out Erwin Moller <Since_humans_read_this_I_am_spammed_too_much@spamyourself.com> - 2011-11-25 10:40 +0100
                          Re: session handler auto log out Denis McMahon <denismfmcmahon@gmail.com> - 2011-11-26 18:36 +0000
      Re: session handler auto log out Erwin Moller <Since_humans_read_this_I_am_spammed_too_much@spamyourself.com> - 2011-11-21 15:41 +0100
        Re: session handler auto log out Arno Welzel <usenet@arnowelzel.de> - 2011-11-21 16:06 +0100

Page 1 of 2  [1] 2  Next page →


#3829 — session handler auto log out

FromDavidB <davidbrotman2768@gmail.com>
Date2011-11-19 14:49 -0800
Subjectsession handler auto log out
Message-ID<11984037.1120.1321742991368.JavaMail.geo-discussion-forums@prlm15>
Hi everyone:

Is there a way to model a session handler to auto logout after a specified period of time without refreshing the page? Something similar to a bank website that auto logs me out and redirects me to another page. 

[toc] | [next] | [standalone]


#3830

FromJerry Stuckle <jstucklex@attglobal.net>
Date2011-11-19 18:29 -0500
Message-ID<ja9e51$v91$1@dont-email.me>
In reply to#3829
On 11/19/2011 5:49 PM, DavidB wrote:
> Hi everyone:
>
> Is there a way to model a session handler to auto logout after a specified period of time without refreshing the page? Something similar to a bank website that auto logs me out and redirects me to another page.

HTTP is a request/response protocol.  While you can set a session 
timeout value on the server, you can't force the client to a different 
page from the server.  It requires a request from the client.

-- 
==================
Remove the "x" from my email address
Jerry Stuckle
JDS Computer Training Corp.
jstucklex@attglobal.net
==================

[toc] | [prev] | [next] | [standalone]


#3831

FromDenis McMahon <denismfmcmahon@gmail.com>
Date2011-11-20 00:11 +0000
Message-ID<4ec845c6$0$28568$a8266bb1@newsreader.readnews.com>
In reply to#3829
On Sat, 19 Nov 2011 14:49:51 -0800, DavidB wrote:

> Is there a way to model a session handler to auto logout after a
> specified period of time without refreshing the page? Something similar
> to a bank website that auto logs me out and redirects me to another
> page.

Yes, but not in the server php.

All you can do in the server php is catch an invalid / unset / expired 
session cookie, assume it related to an expired session, and do the 
redirect when the user tries to reuse the expired session.

On the client side, you can set timeouts in javascript, which is I would 
presume how banks implement such things, but I've never tried doing it 
myself. Perhaps people on comp.lang.javascript could offer suggestions.

Rgds

Denis McMahon

[toc] | [prev] | [next] | [standalone]


#3838

FromArno Welzel <usenet@arnowelzel.de>
Date2011-11-21 15:07 +0100
Message-ID<4ECA5B14.5020200@arnowelzel.de>
In reply to#3829
DavidB, 2011-11-19 23:49:

> Is there a way to model a session handler to auto logout after a specified 
> period of time without refreshing the page? Something similar to a bank
> website that auto logs me out and redirects me to another page.

If you want to force the client to redirect the user to another page as
soon as the session on the *server* times out you must do periodically
checks on the client e.g. using AJAX.


-- 
Arno Welzel
http://arnowelzel.de
http://de-rec-fahrrad.de

[toc] | [prev] | [next] | [standalone]


#3840

FromJerry Stuckle <jstucklex@attglobal.net>
Date2011-11-21 09:13 -0500
Message-ID<jadmbd$uhj$2@dont-email.me>
In reply to#3838
On 11/21/2011 9:07 AM, Arno Welzel wrote:
> DavidB, 2011-11-19 23:49:
>
>> Is there a way to model a session handler to auto logout after a specified
>> period of time without refreshing the page? Something similar to a bank
>> website that auto logs me out and redirects me to another page.
>
> If you want to force the client to redirect the user to another page as
> soon as the session on the *server* times out you must do periodically
> checks on the client e.g. using AJAX.
>
>

Which is not what the op wants.  But both Denis and myself already 
pointed this out two days ago.  What's your point?

-- 
==================
Remove the "x" from my email address
Jerry Stuckle
JDS Computer Training Corp.
jstucklex@attglobal.net
==================

[toc] | [prev] | [next] | [standalone]


#3841

FromArno Welzel <usenet@arnowelzel.de>
Date2011-11-21 15:31 +0100
Message-ID<4ECA60DE.6070301@arnowelzel.de>
In reply to#3840
Jerry Stuckle, 2011-11-21 15:13:

> On 11/21/2011 9:07 AM, Arno Welzel wrote:
>> DavidB, 2011-11-19 23:49:
>>
>>> Is there a way to model a session handler to auto logout after a specified
>>> period of time without refreshing the page? Something similar to a bank
>>> website that auto logs me out and redirects me to another page.
>>
>> If you want to force the client to redirect the user to another page as
>> soon as the session on the *server* times out you must do periodically
>> checks on the client e.g. using AJAX.
>>
>>
> 
> Which is not what the op wants.  But both Denis and myself already 
> pointed this out two days ago.  What's your point?

Using AJAX is not "refreshing the page". You just said "needs a request"
and AJAX is a way to do a request.


-- 
Arno Welzel
http://arnowelzel.de
http://de-rec-fahrrad.de

[toc] | [prev] | [next] | [standalone]


#3846

FromJerry Stuckle <jstucklex@attglobal.net>
Date2011-11-21 12:46 -0500
Message-ID<jae2pp$ptj$1@dont-email.me>
In reply to#3841
On 11/21/2011 9:31 AM, Arno Welzel wrote:
> Jerry Stuckle, 2011-11-21 15:13:
>
>> On 11/21/2011 9:07 AM, Arno Welzel wrote:
>>> DavidB, 2011-11-19 23:49:
>>>
>>>> Is there a way to model a session handler to auto logout after a specified
>>>> period of time without refreshing the page? Something similar to a bank
>>>> website that auto logs me out and redirects me to another page.
>>>
>>> If you want to force the client to redirect the user to another page as
>>> soon as the session on the *server* times out you must do periodically
>>> checks on the client e.g. using AJAX.
>>>
>>>
>>
>> Which is not what the op wants.  But both Denis and myself already
>> pointed this out two days ago.  What's your point?
>
> Using AJAX is not "refreshing the page". You just said "needs a request"
> and AJAX is a way to do a request.
>
>

It is a way which will NOT work.

-- 
==================
Remove the "x" from my email address
Jerry Stuckle
JDS Computer Training Corp.
jstucklex@attglobal.net
==================

[toc] | [prev] | [next] | [standalone]


#3853

FromArno Welzel <usenet@arnowelzel.de>
Date2011-11-22 12:09 +0100
Message-ID<4ECB82D1.2000902@arnowelzel.de>
In reply to#3846
Jerry Stuckle, 2011-11-21 18:46:

> On 11/21/2011 9:31 AM, Arno Welzel wrote:
>> Jerry Stuckle, 2011-11-21 15:13:
>>
>>> On 11/21/2011 9:07 AM, Arno Welzel wrote:
>>>> DavidB, 2011-11-19 23:49:
>>>>
>>>>> Is there a way to model a session handler to auto logout after a specified
>>>>> period of time without refreshing the page? Something similar to a bank
>>>>> website that auto logs me out and redirects me to another page.
>>>>
>>>> If you want to force the client to redirect the user to another page as
>>>> soon as the session on the *server* times out you must do periodically
>>>> checks on the client e.g. using AJAX.
>>>>
>>>>
>>>
>>> Which is not what the op wants.  But both Denis and myself already
>>> pointed this out two days ago.  What's your point?
>>
>> Using AJAX is not "refreshing the page". You just said "needs a request"
>> and AJAX is a way to do a request.
> 
> It is a way which will NOT work.

Why?



-- 
Arno Welzel
http://arnowelzel.de
http://de-rec-fahrrad.de

[toc] | [prev] | [next] | [standalone]


#3854

FromThe Natural Philosopher <tnp@invalid.invalid>
Date2011-11-22 11:18 +0000
Message-ID<jag0el$36a$2@news.albasani.net>
In reply to#3853
Arno Welzel wrote:
> Jerry Stuckle, 2011-11-21 18:46:
> 
>> On 11/21/2011 9:31 AM, Arno Welzel wrote:
>>> Jerry Stuckle, 2011-11-21 15:13:
>>>
>>>> On 11/21/2011 9:07 AM, Arno Welzel wrote:
>>>>> DavidB, 2011-11-19 23:49:
>>>>>
>>>>>> Is there a way to model a session handler to auto logout after a specified
>>>>>> period of time without refreshing the page? Something similar to a bank
>>>>>> website that auto logs me out and redirects me to another page.
>>>>> If you want to force the client to redirect the user to another page as
>>>>> soon as the session on the *server* times out you must do periodically
>>>>> checks on the client e.g. using AJAX.
>>>>>
>>>>>
>>>> Which is not what the op wants.  But both Denis and myself already
>>>> pointed this out two days ago.  What's your point?
>>> Using AJAX is not "refreshing the page". You just said "needs a request"
>>> and AJAX is a way to do a request.
>> It is a way which will NOT work.
> 
> Why?
> 
> 

Because Jerry Says So, And Jerry is Never Wrong.

> 

[toc] | [prev] | [next] | [standalone]


#3861

FromJerry Stuckle <jstucklex@attglobal.net>
Date2011-11-22 07:20 -0500
Message-ID<jag41o$5um$2@dont-email.me>
In reply to#3854
On 11/22/2011 6:18 AM, The Natural Philosopher wrote:
> Arno Welzel wrote:
>> Jerry Stuckle, 2011-11-21 18:46:
>>
>>> On 11/21/2011 9:31 AM, Arno Welzel wrote:
>>>> Jerry Stuckle, 2011-11-21 15:13:
>>>>
>>>>> On 11/21/2011 9:07 AM, Arno Welzel wrote:
>>>>>> DavidB, 2011-11-19 23:49:
>>>>>>
>>>>>>> Is there a way to model a session handler to auto logout after a
>>>>>>> specified
>>>>>>> period of time without refreshing the page? Something similar to
>>>>>>> a bank
>>>>>>> website that auto logs me out and redirects me to another page.
>>>>>> If you want to force the client to redirect the user to another
>>>>>> page as
>>>>>> soon as the session on the *server* times out you must do
>>>>>> periodically
>>>>>> checks on the client e.g. using AJAX.
>>>>>>
>>>>>>
>>>>> Which is not what the op wants. But both Denis and myself already
>>>>> pointed this out two days ago. What's your point?
>>>> Using AJAX is not "refreshing the page". You just said "needs a
>>>> request"
>>>> and AJAX is a way to do a request.
>>> It is a way which will NOT work.
>>
>> Why?
>>
>>
>
> Because Jerry Says So, And Jerry is Never Wrong.
>
>>

There's TNP again.  I knew the troll would show up sooner or later.

Lost another job digging ditches because you couldn't figure out which 
end of the shovel to use?

-- 
==================
Remove the "x" from my email address
Jerry Stuckle
JDS Computer Training Corp.
jstucklex@attglobal.net
==================

[toc] | [prev] | [next] | [standalone]


#3866

FromDenis McMahon <denismfmcmahon@gmail.com>
Date2011-11-22 13:29 +0000
Message-ID<4ecba3ac$0$28579$a8266bb1@newsreader.readnews.com>
In reply to#3861
On Tue, 22 Nov 2011 07:20:01 -0500, Jerry Stuckle wrote:

> Lost another job digging ditches because you couldn't figure out which
> end of the shovel to use?

The end that creates the greater hole to dig himself into of course.

Rgds

Denis McMahon

[toc] | [prev] | [next] | [standalone]


#3860

FromJerry Stuckle <jstucklex@attglobal.net>
Date2011-11-22 07:18 -0500
Message-ID<jag3vp$5um$1@dont-email.me>
In reply to#3853
On 11/22/2011 6:09 AM, Arno Welzel wrote:
> Jerry Stuckle, 2011-11-21 18:46:
>
>> On 11/21/2011 9:31 AM, Arno Welzel wrote:
>>> Jerry Stuckle, 2011-11-21 15:13:
>>>
>>>> On 11/21/2011 9:07 AM, Arno Welzel wrote:
>>>>> DavidB, 2011-11-19 23:49:
>>>>>
>>>>>> Is there a way to model a session handler to auto logout after a specified
>>>>>> period of time without refreshing the page? Something similar to a bank
>>>>>> website that auto logs me out and redirects me to another page.
>>>>>
>>>>> If you want to force the client to redirect the user to another page as
>>>>> soon as the session on the *server* times out you must do periodically
>>>>> checks on the client e.g. using AJAX.
>>>>>
>>>>>
>>>>
>>>> Which is not what the op wants.  But both Denis and myself already
>>>> pointed this out two days ago.  What's your point?
>>>
>>> Using AJAX is not "refreshing the page". You just said "needs a request"
>>> and AJAX is a way to do a request.
>>
>> It is a way which will NOT work.
>
> Why?
>
>
>

Because the AJAX call will reset the session timer, so the session will 
never time out.

It also requires javascript running on the client, which may or may not 
be the case.

And I did not say "refresh the page".  I said "needs a request".  I 
didn't say what KIND of request.


-- g
==================
Remove the "x" from my email address
Jerry Stuckle
JDS Computer Training Corp.
jstucklex@attglobal.net
==================

[toc] | [prev] | [next] | [standalone]


#3867

FromArno Welzel <usenet@arnowelzel.de>
Date2011-11-22 16:55 +0100
Message-ID<4ECBC5FC.4050306@arnowelzel.de>
In reply to#3860
Jerry Stuckle, 2011-11-22 13:18:

> On 11/22/2011 6:09 AM, Arno Welzel wrote:
>> Jerry Stuckle, 2011-11-21 18:46:
>>
>>> On 11/21/2011 9:31 AM, Arno Welzel wrote:
>>>> Jerry Stuckle, 2011-11-21 15:13:
>>>>
>>>>> On 11/21/2011 9:07 AM, Arno Welzel wrote:
>>>>>> DavidB, 2011-11-19 23:49:
>>>>>>
>>>>>>> Is there a way to model a session handler to auto logout after a specified
>>>>>>> period of time without refreshing the page? Something similar to a bank
>>>>>>> website that auto logs me out and redirects me to another page.
>>>>>>
>>>>>> If you want to force the client to redirect the user to another page as
>>>>>> soon as the session on the *server* times out you must do periodically
>>>>>> checks on the client e.g. using AJAX.
>>>>>>
>>>>>>
>>>>>
>>>>> Which is not what the op wants.  But both Denis and myself already
>>>>> pointed this out two days ago.  What's your point?
>>>>
>>>> Using AJAX is not "refreshing the page". You just said "needs a request"
>>>> and AJAX is a way to do a request.
>>>
>>> It is a way which will NOT work.
>>
>> Why?
> 
> Because the AJAX call will reset the session timer, so the session will 
> never time out.

And where did i say that the AJAX call should be *before* the session
times out?

And even if it is implemented this way - why should it not be possible
to implement a server side script which responds to the AJAX calls and
checks the existing session without resetting the session timeout?

Hint: It is also possible to implement a session handling on your own.

> It also requires javascript running on the client, which may or may not 
> be the case.

In this case the automatic redirect will not occur, but the session will
time out anyway.

> And I did not say "refresh the page".  I said "needs a request".  I 
> didn't say what KIND of request.

So using AJAX to send a request is fine ;-)



-- 
Arno Welzel
http://arnowelzel.de
http://de-rec-fahrrad.de

[toc] | [prev] | [next] | [standalone]


#3877

FromJerry Stuckle <jstucklex@attglobal.net>
Date2011-11-22 13:18 -0500
Message-ID<jagp2k$dka$1@dont-email.me>
In reply to#3867
On 11/22/2011 10:55 AM, Arno Welzel wrote:
> Jerry Stuckle, 2011-11-22 13:18:
>
>> On 11/22/2011 6:09 AM, Arno Welzel wrote:
>>> Jerry Stuckle, 2011-11-21 18:46:
>>>
>>>> On 11/21/2011 9:31 AM, Arno Welzel wrote:
>>>>> Jerry Stuckle, 2011-11-21 15:13:
>>>>>
>>>>>> On 11/21/2011 9:07 AM, Arno Welzel wrote:
>>>>>>> DavidB, 2011-11-19 23:49:
>>>>>>>
>>>>>>>> Is there a way to model a session handler to auto logout after a specified
>>>>>>>> period of time without refreshing the page? Something similar to a bank
>>>>>>>> website that auto logs me out and redirects me to another page.
>>>>>>>
>>>>>>> If you want to force the client to redirect the user to another page as
>>>>>>> soon as the session on the *server* times out you must do periodically
>>>>>>> checks on the client e.g. using AJAX.
>>>>>>>
>>>>>>>
>>>>>>
>>>>>> Which is not what the op wants.  But both Denis and myself already
>>>>>> pointed this out two days ago.  What's your point?
>>>>>
>>>>> Using AJAX is not "refreshing the page". You just said "needs a request"
>>>>> and AJAX is a way to do a request.
>>>>
>>>> It is a way which will NOT work.
>>>
>>> Why?
>>
>> Because the AJAX call will reset the session timer, so the session will
>> never time out.
>
> And where did i say that the AJAX call should be *before* the session
> times out?
>

Backpeddling, huh?

> And even if it is implemented this way - why should it not be possible
> to implement a server side script which responds to the AJAX calls and
> checks the existing session without resetting the session timeout?
>

Backpeddling, huh?

> Hint: It is also possible to implement a session handling on your own.
>

Yup, not easy to do, though.

>> It also requires javascript running on the client, which may or may not
>> be the case.
>
> In this case the automatic redirect will not occur, but the session will
> time out anyway.
>

Sure.  As it will if you don't use AJAX at all.

>> And I did not say "refresh the page".  I said "needs a request".  I
>> didn't say what KIND of request.
>
> So using AJAX to send a request is fine ;-)
>
>
>

ROFLMAO!  No, I didn't say AJAX was OK.

Wise up.  You were wrong, but refuse to admit it.

-- 
==================
Remove the "x" from my email address
Jerry Stuckle
JDS Computer Training Corp.
jstucklex@attglobal.net
==================

[toc] | [prev] | [next] | [standalone]


#3884

FromArno Welzel <usenet@arnowelzel.de>
Date2011-11-23 10:17 +0100
Message-ID<4ECCBA39.9070501@arnowelzel.de>
In reply to#3877
Jerry Stuckle, 2011-11-22 19:18:

> On 11/22/2011 10:55 AM, Arno Welzel wrote:
>> Jerry Stuckle, 2011-11-22 13:18:
>>
>>> On 11/22/2011 6:09 AM, Arno Welzel wrote:
>>>> Jerry Stuckle, 2011-11-21 18:46:
>>>>
>>>>> On 11/21/2011 9:31 AM, Arno Welzel wrote:
>>>>>> Jerry Stuckle, 2011-11-21 15:13:
>>>>>>
>>>>>>> On 11/21/2011 9:07 AM, Arno Welzel wrote:
>>>>>>>> DavidB, 2011-11-19 23:49:
>>>>>>>>
>>>>>>>>> Is there a way to model a session handler to auto logout after
>>>>>>>>> a specified
>>>>>>>>> period of time without refreshing the page? Something similar
>>>>>>>>> to a bank
>>>>>>>>> website that auto logs me out and redirects me to another page.
>>>>>>>>
>>>>>>>> If you want to force the client to redirect the user to another
>>>>>>>> page as
>>>>>>>> soon as the session on the *server* times out you must do
>>>>>>>> periodically
>>>>>>>> checks on the client e.g. using AJAX.
>>>>>>>>
>>>>>>>>
>>>>>>>
>>>>>>> Which is not what the op wants.  But both Denis and myself already
>>>>>>> pointed this out two days ago.  What's your point?
>>>>>>
>>>>>> Using AJAX is not "refreshing the page". You just said "needs a
>>>>>> request"
>>>>>> and AJAX is a way to do a request.
>>>>>
>>>>> It is a way which will NOT work.
>>>>
>>>> Why?
>>>
>>> Because the AJAX call will reset the session timer, so the session will
>>> never time out.
>>
>> And where did i say that the AJAX call should be *before* the session
>> times out?
>>
> 
> Backpeddling, huh?

No. You just don't understand it.

>> And even if it is implemented this way - why should it not be possible
>> to implement a server side script which responds to the AJAX calls and
>> checks the existing session without resetting the session timeout?
>>
> 
> Backpeddling, huh?

Nope.

>> Hint: It is also possible to implement a session handling on your own.
>>
> 
> Yup, not easy to do, though.

Recording a timestamp and checking if the time of the last request by
the user (and not only the "check if session is still valid" request) is
not older than x minutes is "not easy"?

[...]
>>> And I did not say "refresh the page".  I said "needs a request".  I
>>> didn't say what KIND of request.
>>
>> So using AJAX to send a request is fine ;-)
> 
> ROFLMAO!  No, I didn't say AJAX was OK.
> 
> Wise up.  You were wrong, but refuse to admit it.

Nope. You just don't understand it.


-- 
Arno Welzel
http://arnowelzel.de
http://de-rec-fahrrad.de

[toc] | [prev] | [next] | [standalone]


#3888

FromJerry Stuckle <jstucklex@attglobal.net>
Date2011-11-23 06:12 -0500
Message-ID<jaikfl$mt9$1@dont-email.me>
In reply to#3884
On 11/23/2011 4:17 AM, Arno Welzel wrote:
> Jerry Stuckle, 2011-11-22 19:18:
>
>> On 11/22/2011 10:55 AM, Arno Welzel wrote:
>>> Jerry Stuckle, 2011-11-22 13:18:
>>>
>>>> On 11/22/2011 6:09 AM, Arno Welzel wrote:
>>>>> Jerry Stuckle, 2011-11-21 18:46:
>>>>>
>>>>>> On 11/21/2011 9:31 AM, Arno Welzel wrote:
>>>>>>> Jerry Stuckle, 2011-11-21 15:13:
>>>>>>>
>>>>>>>> On 11/21/2011 9:07 AM, Arno Welzel wrote:
>>>>>>>>> DavidB, 2011-11-19 23:49:
>>>>>>>>>
>>>>>>>>>> Is there a way to model a session handler to auto logout after
>>>>>>>>>> a specified
>>>>>>>>>> period of time without refreshing the page? Something similar
>>>>>>>>>> to a bank
>>>>>>>>>> website that auto logs me out and redirects me to another page.
>>>>>>>>>
>>>>>>>>> If you want to force the client to redirect the user to another
>>>>>>>>> page as
>>>>>>>>> soon as the session on the *server* times out you must do
>>>>>>>>> periodically
>>>>>>>>> checks on the client e.g. using AJAX.
>>>>>>>>>
>>>>>>>>>
>>>>>>>>
>>>>>>>> Which is not what the op wants.  But both Denis and myself already
>>>>>>>> pointed this out two days ago.  What's your point?
>>>>>>>
>>>>>>> Using AJAX is not "refreshing the page". You just said "needs a
>>>>>>> request"
>>>>>>> and AJAX is a way to do a request.
>>>>>>
>>>>>> It is a way which will NOT work.
>>>>>
>>>>> Why?
>>>>
>>>> Because the AJAX call will reset the session timer, so the session will
>>>> never time out.
>>>
>>> And where did i say that the AJAX call should be *before* the session
>>> times out?
>>>
>>
>> Backpeddling, huh?
>
> No. You just don't understand it.
>

I understand completely, backpeddler.

>>> And even if it is implemented this way - why should it not be possible
>>> to implement a server side script which responds to the AJAX calls and
>>> checks the existing session without resetting the session timeout?
>>>
>>
>> Backpeddling, huh?
>
> Nope.
>

Yep.

>>> Hint: It is also possible to implement a session handling on your own.
>>>
>>
>> Yup, not easy to do, though.
>
> Recording a timestamp and checking if the time of the last request by
> the user (and not only the "check if session is still valid" request) is
> not older than x minutes is "not easy"?
>

A lot more to it than that, if you actually understood session handling.

> [...]
>>>> And I did not say "refresh the page".  I said "needs a request".  I
>>>> didn't say what KIND of request.
>>>
>>> So using AJAX to send a request is fine ;-)
>>
>> ROFLMAO!  No, I didn't say AJAX was OK.
>>
>> Wise up.  You were wrong, but refuse to admit it.
>
> Nope. You just don't understand it.
>
>

I understand completely, backpeddler.

-- 
==================
Remove the "x" from my email address
Jerry Stuckle
JDS Computer Training Corp.
jstucklex@attglobal.net
==================

[toc] | [prev] | [next] | [standalone]


#3891

FromArno Welzel <usenet@arnowelzel.de>
Date2011-11-23 16:04 +0100
Message-ID<4ECD0B7F.6000803@arnowelzel.de>
In reply to#3888
Jerry Stuckle, 2011-11-23 12:12:

> On 11/23/2011 4:17 AM, Arno Welzel wrote:
>> Jerry Stuckle, 2011-11-22 19:18:
>>
>>> On 11/22/2011 10:55 AM, Arno Welzel wrote:
>>>> Jerry Stuckle, 2011-11-22 13:18:
>>>>
>>>>> On 11/22/2011 6:09 AM, Arno Welzel wrote:
>>>>>> Jerry Stuckle, 2011-11-21 18:46:
>>>>>>
>>>>>>> On 11/21/2011 9:31 AM, Arno Welzel wrote:
>>>>>>>> Jerry Stuckle, 2011-11-21 15:13:
>>>>>>>>
>>>>>>>>> On 11/21/2011 9:07 AM, Arno Welzel wrote:
>>>>>>>>>> DavidB, 2011-11-19 23:49:
>>>>>>>>>>
>>>>>>>>>>> Is there a way to model a session handler to auto logout after
>>>>>>>>>>> a specified
>>>>>>>>>>> period of time without refreshing the page? Something similar
>>>>>>>>>>> to a bank
>>>>>>>>>>> website that auto logs me out and redirects me to another page.
>>>>>>>>>>
>>>>>>>>>> If you want to force the client to redirect the user to another
>>>>>>>>>> page as
>>>>>>>>>> soon as the session on the *server* times out you must do
>>>>>>>>>> periodically
>>>>>>>>>> checks on the client e.g. using AJAX.
>>>>>>>>>>
>>>>>>>>>>
>>>>>>>>>
>>>>>>>>> Which is not what the op wants.  But both Denis and myself already
>>>>>>>>> pointed this out two days ago.  What's your point?
>>>>>>>>
>>>>>>>> Using AJAX is not "refreshing the page". You just said "needs a
>>>>>>>> request"
>>>>>>>> and AJAX is a way to do a request.
>>>>>>>
>>>>>>> It is a way which will NOT work.
>>>>>>
>>>>>> Why?
>>>>>
>>>>> Because the AJAX call will reset the session timer, so the session will
>>>>> never time out.
>>>>
>>>> And where did i say that the AJAX call should be *before* the session
>>>> times out?
>>>>
>>>
>>> Backpeddling, huh?
>>
>> No. You just don't understand it.
>>
> 
> I understand completely, backpeddler.
> 
>>>> And even if it is implemented this way - why should it not be possible
>>>> to implement a server side script which responds to the AJAX calls and
>>>> checks the existing session without resetting the session timeout?
>>>>
>>>
>>> Backpeddling, huh?
>>
>> Nope.
>>
> 
> Yep.

You still don't get it.

>>>> Hint: It is also possible to implement a session handling on your own.
>>>>
>>>
>>> Yup, not easy to do, though.
>>
>> Recording a timestamp and checking if the time of the last request by
>> the user (and not only the "check if session is still valid" request) is
>> not older than x minutes is "not easy"?
>>
> 
> A lot more to it than that, if you actually understood session handling.

I do.

>> [...]
>>>>> And I did not say "refresh the page".  I said "needs a request".  I
>>>>> didn't say what KIND of request.
>>>>
>>>> So using AJAX to send a request is fine ;-)
>>>
>>> ROFLMAO!  No, I didn't say AJAX was OK.
>>>
>>> Wise up.  You were wrong, but refuse to admit it.
>>
>> Nope. You just don't understand it.
> 
> I understand completely, backpeddler.

No you don't. You said:

"While you can set a session timeout value on the server, you can't
force the client to a different page from the server.  It requires a
request from the client."

You don't understand because you assume that any request will *always*
reset the session timeout and you assume that relying on PHPs own
session handling is the only way to go.


-- 
Arno Welzel
http://arnowelzel.de
http://de-rec-fahrrad.de

[toc] | [prev] | [next] | [standalone]


#3892

FromJerry Stuckle <jstucklex@attglobal.net>
Date2011-11-23 10:39 -0500
Message-ID<jaj43a$m1j$1@dont-email.me>
In reply to#3891
On 11/23/2011 10:04 AM, Arno Welzel wrote:
> Jerry Stuckle, 2011-11-23 12:12:
>
>> On 11/23/2011 4:17 AM, Arno Welzel wrote:
>>> Jerry Stuckle, 2011-11-22 19:18:
>>>
>>>> On 11/22/2011 10:55 AM, Arno Welzel wrote:
>>>>> Jerry Stuckle, 2011-11-22 13:18:
>>>>>
>>>>>> On 11/22/2011 6:09 AM, Arno Welzel wrote:
>>>>>>> Jerry Stuckle, 2011-11-21 18:46:
>>>>>>>
>>>>>>>> On 11/21/2011 9:31 AM, Arno Welzel wrote:
>>>>>>>>> Jerry Stuckle, 2011-11-21 15:13:
>>>>>>>>>
>>>>>>>>>> On 11/21/2011 9:07 AM, Arno Welzel wrote:
>>>>>>>>>>> DavidB, 2011-11-19 23:49:
>>>>>>>>>>>
>>>>>>>>>>>> Is there a way to model a session handler to auto logout after
>>>>>>>>>>>> a specified
>>>>>>>>>>>> period of time without refreshing the page? Something similar
>>>>>>>>>>>> to a bank
>>>>>>>>>>>> website that auto logs me out and redirects me to another page.
>>>>>>>>>>>
>>>>>>>>>>> If you want to force the client to redirect the user to another
>>>>>>>>>>> page as
>>>>>>>>>>> soon as the session on the *server* times out you must do
>>>>>>>>>>> periodically
>>>>>>>>>>> checks on the client e.g. using AJAX.
>>>>>>>>>>>
>>>>>>>>>>>
>>>>>>>>>>
>>>>>>>>>> Which is not what the op wants.  But both Denis and myself already
>>>>>>>>>> pointed this out two days ago.  What's your point?
>>>>>>>>>
>>>>>>>>> Using AJAX is not "refreshing the page". You just said "needs a
>>>>>>>>> request"
>>>>>>>>> and AJAX is a way to do a request.
>>>>>>>>
>>>>>>>> It is a way which will NOT work.
>>>>>>>
>>>>>>> Why?
>>>>>>
>>>>>> Because the AJAX call will reset the session timer, so the session will
>>>>>> never time out.
>>>>>
>>>>> And where did i say that the AJAX call should be *before* the session
>>>>> times out?
>>>>>
>>>>
>>>> Backpeddling, huh?
>>>
>>> No. You just don't understand it.
>>>
>>
>> I understand completely, backpeddler.
>>
>>>>> And even if it is implemented this way - why should it not be possible
>>>>> to implement a server side script which responds to the AJAX calls and
>>>>> checks the existing session without resetting the session timeout?
>>>>>
>>>>
>>>> Backpeddling, huh?
>>>
>>> Nope.
>>>
>>
>> Yep.
>
> You still don't get it.
>
>>>>> Hint: It is also possible to implement a session handling on your own.
>>>>>
>>>>
>>>> Yup, not easy to do, though.
>>>
>>> Recording a timestamp and checking if the time of the last request by
>>> the user (and not only the "check if session is still valid" request) is
>>> not older than x minutes is "not easy"?
>>>
>>
>> A lot more to it than that, if you actually understood session handling.
>
> I do.
>
>>> [...]
>>>>>> And I did not say "refresh the page".  I said "needs a request".  I
>>>>>> didn't say what KIND of request.
>>>>>
>>>>> So using AJAX to send a request is fine ;-)
>>>>
>>>> ROFLMAO!  No, I didn't say AJAX was OK.
>>>>
>>>> Wise up.  You were wrong, but refuse to admit it.
>>>
>>> Nope. You just don't understand it.
>>
>> I understand completely, backpeddler.
>
> No you don't. You said:
>
> "While you can set a session timeout value on the server, you can't
> force the client to a different page from the server.  It requires a
> request from the client."
>
> You don't understand because you assume that any request will *always*
> reset the session timeout and you assume that relying on PHPs own
> session handling is the only way to go.
>
>

No, but I also know that any request which does not reset the timeout 
does not cause a redirect.

We are talking PHP sessions here, not something you've cobbled up on the 
side.  And that's how PHP sessions work.


-- 
==================
Remove the "x" from my email address
Jerry Stuckle
JDS Computer Training Corp.
jstucklex@attglobal.net
==================

[toc] | [prev] | [next] | [standalone]


#3896

FromDenis McMahon <denismfmcmahon@gmail.com>
Date2011-11-23 18:58 +0000
Message-ID<4ecd4241$0$28492$a8266bb1@newsreader.readnews.com>
In reply to#3884
On Wed, 23 Nov 2011 10:17:45 +0100, Arno Welzel wrote:

>>> Hint: It is also possible to implement a session handling on your own.

>> Yup, not easy to do, though.

> Recording a timestamp and checking if the time of the last request by
> the user (and not only the "check if session is still valid" request) is
> not older than x minutes is "not easy"?

and the session variables?

Rgds

Denis McMahon

[toc] | [prev] | [next] | [standalone]


#3899

FromArno Welzel <usenet@arnowelzel.de>
Date2011-11-23 20:42 +0100
Message-ID<4ECD4CB0.5020903@arnowelzel.de>
In reply to#3896
Denis McMahon, 2011-11-23 19:58:

> On Wed, 23 Nov 2011 10:17:45 +0100, Arno Welzel wrote:
> 
>>>> Hint: It is also possible to implement a session handling on your own.
> 
>>> Yup, not easy to do, though.
> 
>> Recording a timestamp and checking if the time of the last request by
>> the user (and not only the "check if session is still valid" request) is
>> not older than x minutes is "not easy"?
> 
> and the session variables?

They get lost, as soon as the PHP session times out of course - but by
doing periodically request using JavaScript this will not happen, so one
has to implement additional logic to maintain your application specific
session timeout and to distinguish between the periodically session
checks via JavaScript and "real" requests caused by user interaction.

In case JavaScript is not available, the session will just time out, any
session variable will be lost and usually the redirection to a "session
timed out" page will be done using the referrer which indicates the
previous page was one which is only accessible for logged in users.

If there is even no referrer you can not distinguish between a session
timeout or a new session and you have to redirect to a general login
page, maybe with an additional explanation like "maybe your session
timed out because we did not receive any request for more than 5
minutes" or similar.


-- 
Arno Welzel
http://arnowelzel.de
http://de-rec-fahrrad.de

[toc] | [prev] | [next] | [standalone]


Page 1 of 2  [1] 2  Next page →

Back to top | Article view | comp.lang.php


csiph-web