Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > comp.lang.php > #3892
| From | Jerry Stuckle <jstucklex@attglobal.net> |
|---|---|
| Newsgroups | comp.lang.php |
| Subject | Re: session handler auto log out |
| Date | 2011-11-23 10:39 -0500 |
| Organization | A noiseless patient Spider |
| Message-ID | <jaj43a$m1j$1@dont-email.me> (permalink) |
| References | (7 earlier) <4ECBC5FC.4050306@arnowelzel.de> <jagp2k$dka$1@dont-email.me> <4ECCBA39.9070501@arnowelzel.de> <jaikfl$mt9$1@dont-email.me> <4ECD0B7F.6000803@arnowelzel.de> |
On 11/23/2011 10:04 AM, Arno Welzel wrote: > Jerry Stuckle, 2011-11-23 12:12: > >> On 11/23/2011 4:17 AM, Arno Welzel wrote: >>> Jerry Stuckle, 2011-11-22 19:18: >>> >>>> On 11/22/2011 10:55 AM, Arno Welzel wrote: >>>>> Jerry Stuckle, 2011-11-22 13:18: >>>>> >>>>>> On 11/22/2011 6:09 AM, Arno Welzel wrote: >>>>>>> Jerry Stuckle, 2011-11-21 18:46: >>>>>>> >>>>>>>> On 11/21/2011 9:31 AM, Arno Welzel wrote: >>>>>>>>> Jerry Stuckle, 2011-11-21 15:13: >>>>>>>>> >>>>>>>>>> On 11/21/2011 9:07 AM, Arno Welzel wrote: >>>>>>>>>>> DavidB, 2011-11-19 23:49: >>>>>>>>>>> >>>>>>>>>>>> Is there a way to model a session handler to auto logout after >>>>>>>>>>>> a specified >>>>>>>>>>>> period of time without refreshing the page? Something similar >>>>>>>>>>>> to a bank >>>>>>>>>>>> website that auto logs me out and redirects me to another page. >>>>>>>>>>> >>>>>>>>>>> If you want to force the client to redirect the user to another >>>>>>>>>>> page as >>>>>>>>>>> soon as the session on the *server* times out you must do >>>>>>>>>>> periodically >>>>>>>>>>> checks on the client e.g. using AJAX. >>>>>>>>>>> >>>>>>>>>>> >>>>>>>>>> >>>>>>>>>> Which is not what the op wants. But both Denis and myself already >>>>>>>>>> pointed this out two days ago. What's your point? >>>>>>>>> >>>>>>>>> Using AJAX is not "refreshing the page". You just said "needs a >>>>>>>>> request" >>>>>>>>> and AJAX is a way to do a request. >>>>>>>> >>>>>>>> It is a way which will NOT work. >>>>>>> >>>>>>> Why? >>>>>> >>>>>> Because the AJAX call will reset the session timer, so the session will >>>>>> never time out. >>>>> >>>>> And where did i say that the AJAX call should be *before* the session >>>>> times out? >>>>> >>>> >>>> Backpeddling, huh? >>> >>> No. You just don't understand it. >>> >> >> I understand completely, backpeddler. >> >>>>> And even if it is implemented this way - why should it not be possible >>>>> to implement a server side script which responds to the AJAX calls and >>>>> checks the existing session without resetting the session timeout? >>>>> >>>> >>>> Backpeddling, huh? >>> >>> Nope. >>> >> >> Yep. > > You still don't get it. > >>>>> Hint: It is also possible to implement a session handling on your own. >>>>> >>>> >>>> Yup, not easy to do, though. >>> >>> Recording a timestamp and checking if the time of the last request by >>> the user (and not only the "check if session is still valid" request) is >>> not older than x minutes is "not easy"? >>> >> >> A lot more to it than that, if you actually understood session handling. > > I do. > >>> [...] >>>>>> And I did not say "refresh the page". I said "needs a request". I >>>>>> didn't say what KIND of request. >>>>> >>>>> So using AJAX to send a request is fine ;-) >>>> >>>> ROFLMAO! No, I didn't say AJAX was OK. >>>> >>>> Wise up. You were wrong, but refuse to admit it. >>> >>> Nope. You just don't understand it. >> >> I understand completely, backpeddler. > > No you don't. You said: > > "While you can set a session timeout value on the server, you can't > force the client to a different page from the server. It requires a > request from the client." > > You don't understand because you assume that any request will *always* > reset the session timeout and you assume that relying on PHPs own > session handling is the only way to go. > > No, but I also know that any request which does not reset the timeout does not cause a redirect. We are talking PHP sessions here, not something you've cobbled up on the side. And that's how PHP sessions work. -- ================== Remove the "x" from my email address Jerry Stuckle JDS Computer Training Corp. jstucklex@attglobal.net ==================
Back to comp.lang.php | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread
session handler auto log out DavidB <davidbrotman2768@gmail.com> - 2011-11-19 14:49 -0800
Re: session handler auto log out Jerry Stuckle <jstucklex@attglobal.net> - 2011-11-19 18:29 -0500
Re: session handler auto log out Denis McMahon <denismfmcmahon@gmail.com> - 2011-11-20 00:11 +0000
Re: session handler auto log out Arno Welzel <usenet@arnowelzel.de> - 2011-11-21 15:07 +0100
Re: session handler auto log out Jerry Stuckle <jstucklex@attglobal.net> - 2011-11-21 09:13 -0500
Re: session handler auto log out Arno Welzel <usenet@arnowelzel.de> - 2011-11-21 15:31 +0100
Re: session handler auto log out Jerry Stuckle <jstucklex@attglobal.net> - 2011-11-21 12:46 -0500
Re: session handler auto log out Arno Welzel <usenet@arnowelzel.de> - 2011-11-22 12:09 +0100
Re: session handler auto log out The Natural Philosopher <tnp@invalid.invalid> - 2011-11-22 11:18 +0000
Re: session handler auto log out Jerry Stuckle <jstucklex@attglobal.net> - 2011-11-22 07:20 -0500
Re: session handler auto log out Denis McMahon <denismfmcmahon@gmail.com> - 2011-11-22 13:29 +0000
Re: session handler auto log out Jerry Stuckle <jstucklex@attglobal.net> - 2011-11-22 07:18 -0500
Re: session handler auto log out Arno Welzel <usenet@arnowelzel.de> - 2011-11-22 16:55 +0100
Re: session handler auto log out Jerry Stuckle <jstucklex@attglobal.net> - 2011-11-22 13:18 -0500
Re: session handler auto log out Arno Welzel <usenet@arnowelzel.de> - 2011-11-23 10:17 +0100
Re: session handler auto log out Jerry Stuckle <jstucklex@attglobal.net> - 2011-11-23 06:12 -0500
Re: session handler auto log out Arno Welzel <usenet@arnowelzel.de> - 2011-11-23 16:04 +0100
Re: session handler auto log out Jerry Stuckle <jstucklex@attglobal.net> - 2011-11-23 10:39 -0500
Re: session handler auto log out Denis McMahon <denismfmcmahon@gmail.com> - 2011-11-23 18:58 +0000
Re: session handler auto log out Arno Welzel <usenet@arnowelzel.de> - 2011-11-23 20:42 +0100
Re: session handler auto log out Denis McMahon <denismfmcmahon@gmail.com> - 2011-11-23 23:07 +0000
Re: session handler auto log out Jerry Stuckle <jstucklex@attglobal.net> - 2011-11-23 23:57 -0500
Re: session handler auto log out Arno Welzel <usenet@arnowelzel.de> - 2011-11-24 09:53 +0100
Re: session handler auto log out Arno Welzel <usenet@arnowelzel.de> - 2011-11-24 11:19 +0100
Re: session handler auto log out Arno Welzel <usenet@arnowelzel.de> - 2011-11-24 09:47 +0100
Re: session handler auto log out Denis McMahon <denismfmcmahon@gmail.com> - 2011-11-23 02:09 +0000
Re: session handler auto log out Arno Welzel <usenet@arnowelzel.de> - 2011-11-23 10:22 +0100
Re: session handler auto log out Erwin Moller <Since_humans_read_this_I_am_spammed_too_much@spamyourself.com> - 2011-11-23 10:55 +0100
Re: session handler auto log out Denis McMahon <denismfmcmahon@gmail.com> - 2011-11-23 18:53 +0000
Re: session handler auto log out Erwin Moller <Since_humans_read_this_I_am_spammed_too_much@spamyourself.com> - 2011-11-25 10:40 +0100
Re: session handler auto log out Denis McMahon <denismfmcmahon@gmail.com> - 2011-11-26 18:36 +0000
Re: session handler auto log out Erwin Moller <Since_humans_read_this_I_am_spammed_too_much@spamyourself.com> - 2011-11-21 15:41 +0100
Re: session handler auto log out Arno Welzel <usenet@arnowelzel.de> - 2011-11-21 16:06 +0100
csiph-web