Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > comp.lang.php > #17743
| From | Thomas 'PointedEars' Lahn <PointedEars@web.de> |
|---|---|
| Newsgroups | comp.lang.php |
| Subject | Re: php ini |
| Date | 2018-05-16 19:59 +0200 |
| Organization | PointedEars Software (PES) |
| Message-ID | <13761023.FnKYLD8mAL@PointedEars.de> (permalink) |
| References | <pdh718$u78$1@dont-email.me> <pdhfpq$l5h$1@dont-email.me> <1731736.ES7vfGFGlS@PointedEars.de> <pdhkmp$s7c$1@dont-email.me> |
Lew Pitcher wrote:
> Thomas 'PointedEars' Lahn wrote:
>> Lew Pitcher wrote:
>>> You are looking for the "session.cookie_lifetime" setting in php.ini
>>
>> Not necessarily.
Because that setting is not the only one that controls the availability of
session information.
>>> […]
>>> http://php.net/manual/en/session.configuration.php
>>>
>>> [snip]
>>>
>>> FWIW, this is a global php setting;
>>
>> It does not have to.
>
> Yes, it does.
>
> You can /override/ the setting, but that takes a deliberate act.
I would assume that depends on how the PHP executable is compiled.
>>> if you have multiple pages,
>> You mean Web _sites_.
>
> No, I mean multiple pages.
First of all, *there* *are* *no* (*Web*) *pages*. Get rid of that outdated
concept NOW.
Second, it is a bad idea for different parts of the same Web site to have
different session lifetimes, unless they are part of distinct applications
that are presented as such to the user.
Even then, users usually expect a Web site, and in a broader context, a Web
application as a service to other Web resources, to work consistently
throughout. If the session is the result of a login process, they will not
appreciate that this session times out earlier in one section of the Web
site or one feature of the Web service than in another.
>>> each with their own session criteria, you can override this default by
>>> passing the appropriate value in the session_start() call.
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
>> (They said that they do not want to do it in code.)
>
> Yes, so?
So this particular suggestion is the exact opposite of what the OP is
looking for. (Is that not blatantly obvious?)
One valid reason why one would not want to do it in code is that the code
must not or is not supposed to be modified.
> My answer stands: use the "session.cookie_lifetime" setting in
> php.ini
If one does that, then that affects all parts of all sites hosted on the
same (virtual) server. Bad idea, and often not even possible as prevented
by administrative locks.
>> Provide an additional configuration (file) for each site instead.
>
> What sort of "configuration (file)"?
This setting and many other session-related settings have a changeable mode
of PHP_INI_ALL, which means that they can be set in php.ini and in PHP
source code, but also in httpd.conf (including the virtual host
configuration), and per directory in a .htaccess or .user.ini file
(therefore, “file” in parentheses).
> And, how do /you/ control separate sessions per page (yes, you /can/ do
> that)?
That depends on what *you* mean by “page”. This term is underdefined at
best.
For different dynamically generated Web documents, that belong to the same
application, I would not do it.
For distinct applications, using different session.save_path, which also can
be be set in one of the ways that I described above; preferably _not_ in
php.ini or code. In fact, different session directiories is the recommended
approach, so that different sessions of different applications on the same
server do not interfere, can expire, be garbage collected, and be reset
manually if necessary, independently.
--
PointedEars
Zend Certified PHP Engineer <http://www.zend.com/en/yellow-pages/ZEND024953>
<https://github.com/PointedEars> | <http://PointedEars.de/wsvn>
Twitter: @PointedEars2 | Please do not cc me./Bitte keine Kopien per E-Mail.
Back to comp.lang.php | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread
php ini madwomans Dad <dsvirtual58@gmail.com> - 2018-05-16 13:09 +0100
Re: php ini tony@mountifield.org (Tony Mountifield) - 2018-05-16 13:11 +0000
Re: php ini K <yyyyyeeeee00000@writeme.com> - 2023-03-11 07:53 -0800
Re: php ini doctor@doctor.nl2k.ab.ca (The Doctor) - 2023-03-11 23:44 +0000
Re: php ini Lew Pitcher <lew.pitcher@digitalfreehold.ca> - 2018-05-16 10:38 -0400
Re: php ini Thomas 'PointedEars' Lahn <PointedEars@web.de> - 2018-05-16 16:53 +0200
Re: php ini Lew Pitcher <lew.pitcher@digitalfreehold.ca> - 2018-05-16 12:02 -0400
Re: php ini Thomas 'PointedEars' Lahn <PointedEars@web.de> - 2018-05-16 19:59 +0200
Re: php ini Jerry Stuckle <jstucklex@attglobal.net> - 2018-05-16 15:09 -0400
Re: php ini "J.O. Aho" <user@example.net> - 2018-05-16 18:29 +0200
Re: php ini Thomas 'PointedEars' Lahn <PointedEars@web.de> - 2018-05-16 16:48 +0200
Re: php ini "J.O. Aho" <user@example.net> - 2018-05-16 18:36 +0200
Re: php ini madwomans Dad <dsvirtual58@gmail.com> - 2018-05-17 08:42 +0100
csiph-web