Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > comp.lang.php > #4313
| From | Arno Welzel <usenet@arnowelzel.de> |
|---|---|
| Newsgroups | comp.lang.php |
| Subject | Re: sessions timeout |
| Date | 2012-01-08 20:17 +0100 |
| Organization | A noiseless patient Spider |
| Message-ID | <4F09EBE6.3060907@arnowelzel.de> (permalink) |
| References | <66b7g7lk434p6vk68429d8np5134jd52hd@4ax.com> <4F040BE5.7000207@arnowelzel.de> <je1avb$l8$1@news.albasani.net> |
The Natural Philosopher, 2012-01-04 11:51: [...] > Basically the code needs to do as a common FIRST THING in EVERY access > > get the cookie name/value pair and search your database for a value that > matches it, and is less than X minutes since it was stored in the database. Which means, nearly *every* access will result in a database access. [...] > I am sure you can get sessions to behave in this way, but it seems to me > its a poor substitute for a database, if you have one. For me it seems to be the opposite: A session can make things a lot easier, since you don't have to handle hundrets or thousands of database queries. Of course it makes sense to use a database to store user accounts - but it should only be checked *once* at the time of login and not at *every* request by the user. I alread did an example for session timeout handling a while ago - well, it also demonstrates using JavaScript to automatically tell the user that the session timed out, but it also works without JavaScript: See <http://arnowelzel.de/samples/sessiondemo.php> -- Arno Welzel http://arnowelzel.de http://de-rec-fahrrad.de
Back to comp.lang.php | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread
sessions timeout Michael Joel <no@please.com> - 2012-01-03 20:42 -0500
Re: sessions timeout gordonb.bqidf@burditt.org (Gordon Burditt) - 2012-01-03 22:23 -0600
Re: sessions timeout Arno Welzel <usenet@arnowelzel.de> - 2012-01-04 09:20 +0100
Re: sessions timeout The Natural Philosopher <tnp@invalid.invalid> - 2012-01-04 10:51 +0000
Re: sessions timeout Arno Welzel <usenet@arnowelzel.de> - 2012-01-08 20:17 +0100
Re: sessions timeout Jerry Stuckle <jstucklex@attglobal.net> - 2012-01-04 06:54 -0500
csiph-web