Developing State-enabled Applications With PHP


John L

Installment 1

Developing State-enabled Applications With PHP

When a user is browsing through a website and is surfing from one web page to another, sometimes the website needs to remember the actions e.g. choices performed by the user. For example, in a website that sells DVDs, the user typically browses through a list of DVDs and selects individual DVDs for check out at the end of the shopping session. The website needs to remember which DVDs the user has selected because the selected items needs to be presented again to the user when the user checks out. In other words, the website needs to remember the State - i.e. the selected items - of the users browsing activities.

However, HTTP is a Stateless protocol and is ill-equipped to handle States. A standard HTML website basically provides information to the user and a series of links that simply directs the user to other related web pages. This Stateless nature of HTTP allows the website to be replicated across many servers for load balancing purposes. A major drawback is that while browsing from one page to another, the website does not remember the State of the browsing session. This make interactivity almost impossible.

In order to increase interactivity, the developer can use the session handling features of PHP to augment the features of HTTP in order to remember the State of the browsing session. The are basically 2 ways PHP does this:

  1. Using cookies
  2. Using Sessions

The next installment discusses how to manage sessions using cookies...

Installment 2

Cookies

Cookies are used to store State-information in the browser. Browsers are allowed to keep up to 20 cookies for each domain and the values stored in the cookie cannot exceed 4 KB. If more than 20 cookies are created by the website, only the latest 20 are stored. Cookies are only suitable in instances that do not require complex session communications and are not favoured by some developers because of privacy issues. Furthermore, some users disable support for cookies at their browsers.

The following is a typical server-browser sequence of events that occur when a cookie is used:

  1. The server knows that it needs to remember the State of browsing session
  2. The server creates a cookie and uses the Set-Cookie header field in the HTTP response to pass the cookie to the browser
  3. The browser reads the cookie field in the HTTP response and stores the cookie
  4. This cookie information is passed along future browser-server communications and can be used in the PHP scripts as a variable

PHP provides a function called setcookie to allow easy creation of cookies. The syntax for setcookie is:

int setcookiestring name, [string val], [int expiration_date], [string path], string domain, [int secure]

The parameters are:

  1. name - this is a mandatory parameter and is used subsequently to identify the cookie
  2. value - the value of the cookie - e.g. if the cookie is used to store the name of the user, the value parameter will store the actual name - e.g. John
  3. expiration_date - the lifetime of the cookie. After this date, the cookie expires and is unusable
  4. path - the path refers to the URL from which the cookie is valid and allowed
  5. domain - the domain the created the cookie and is allowed to read the contents of the cookie
  6. secure - specifies if the cookie can be sent only through a secure connection - e.g. SSL enable sessions

The following is an example that displays to the user how many times a specific web page has been displayed to the user. Copy the code below both the php and the html into a file with the .php extension and test it out.


[php

//check if the $count variable has been associated with the count cookie

if !isset$count {

    $count = 0;

} else {

    $count++;

}

setcookie"count", $count, time+600, "/", "", 0;

]



[html]

    [head]

        [title]Session Handling Using Cookies[/title]

    [/head]

    [body]

        This page has been displayed: [=$count ] times.

    [/body]

[/html]

The next installment discusses how to manage sessions using PHP session handling functions with cookies enabled...

Installment 3

PHP Session Handling - Cookies Enabled

Instead of storing session information at the browser through the use of cookies, the information can instead be stored at the server in session files. One session file is created and maintained for each user session. For example, if there are three concurrent users browsing the website, three session files will be created and maintained - one for each user. The session files are deleted if the session is explicitly closed by the PHP script or by a daemon garbage collection process provided by PHP. Good programming practice would call for sessions to be closed explicitly in the script.

The following is a typical server-browser sequence of events that occur when a PHP session handling is used:

  1. The server knows that it needs to remember the State of browsing session
  2. PHP generates a sssion ID and creates a session file to store future information as required by subsequent pages
  3. A cookie is generated wih the session ID at the browser
  4. This cookie that stores the session ID is transparently and automatically sent to the server for all subsequent requests to the server

The following PHP session-handling example accomplishes the same outcome as the previous cookie example. Copy the code below both the php and the html into a file with the .php extension and test it out.

[php //starts a session session_start; //informs PHP that count information needs to be remembered in the session file if !session_is_registered"count" { session_register"count"; $count = 0; } else { $count++; } $session_id = session_id; ] [html] [head] [title]PHP Session Handling - Cookie-Enabled[/title] [/head] [body] The current session id is: [=$session_id ] This page has been displayed: [=$count ] times. [/body] [/html]

A summary of the functions that PHP provides for session handling are:

  1. boolean start_session - initializes a session
  2. string session_id[string id] - either returns the current session id or specify the session id to be used when the session is created
  3. boolean session_registermixed name [, mixed ...] - registers variables to be stored in the session file. Each parameter passed in the function is a separate variable
  4. boolean session_is_registeredstring variable_name - checks if a variable has been previously registered to be stored in the session file
  5. session_unregisterstring varriable_name - unregisters a variable from the session file. Unregistered variables are no longer valid for reference in the session.
  6. session_unset - unsets all session variables. It is important to note that all the variables remain registered.
  7. boolean session_destroy - destroys the session. This is opposite of the start_session function.

The next installment discusses how to manage sessions using PHP session handling functions when cookies are disabled...

Installment 4

PHP Session Handling - Without Cookies

If cookies are disabled at the browser, the above example cannot work. This is because although the session file that stores all the variables is kept at the server, a cookie is still needed at the browser to store the session ID that is used to identify the session and its associated session file. The most common way around this would be to explicitly pass the session ID back to the server from the browser as a query parameter in the URL.

For example, the PHP script generates requests subsequent to the start_session call in the following format:

http://www.yourhost.com/yourphpfile.phpPHPSESSID=[actual session ID]

The following are excerpts that illustrate the discussion:

Manually building the URL:

$url = "http://www.yoursite.com/yourphppage.phpPHPSESSID=" . session_id;
[a href="[=$url ]"]Anchor Text[/a]

Building the URL using SID:

[a href="http://www.yoursite.com/yourphppage.php[=SID ]"]Anchor Text[/a]





About The Author

John L is the webmaster of http://www.bimmercenter.com..

daboss@bimmercenter.com



To provide some examples of web design and development I give you here:

10 latest blog posts by Web Developer Jim Westergren

I’m an SEO and I have been working a lot with WordPress, here I give you all my tips for you to rank very well in Google with your blog. UPDATE: Check this blog post for a better guide. Quick Facts There are 55 million blogs out there, if you don’t stand out you will have no chance. The [...]

Update, March 9th I have now changed it again and put some color into it. What do you guys think? Sunday today and I was away from work with clients so I decided to work with my blog today from home. I made a new design for this site. Check out the navigation links at the top left [...]

This article is written for my friend “honey” (site). I have been bidding against honey on web site auctions for almost 2 years now. I have won maybe 60 auctions and I have now over 100 web sites. Honey owns over 300 … So here comes my checklist that I want to show honey as I [...]

Have you also heard of those horror stories of Google banning Adsense accounts for the smallest mistakes? You have read the Terms and Conditions and you know the basics but what do you do when you show your friend your site on your computer and the first thing he does is to click the Adsense ad [...]

This article is written more for myself so I remember how I do it the next time but probably a few people will also benefit from this for different uses and purposes. Today I updated all the PR values for the directories listed on my directory list. I had to update each listing in the MySQL [...]

Official site of a children’s hospital in Japan Hey, your “logo” is not blinking! MSY Technology Pty. Ltd. Are you sure product X is HOT? Personal site of Franz Magnus Incredible that you got several awards for that site. Angren.net, electronic shop Can’t you squeeze in something more on the home page? Official site of Northbridge Police Department Still being updated in 2006. Perhaps [...]

The last days I have been fighting in the war against the latest spam bot soldiers like a maniac. I own and manage over 70 web sites. This includes different forums, directories, blogs, topsites, article submission sites and you name it. Very recently there is a new wave of spam. The default captcha for vBulletin is now [...]

This is a WordPress plugin that will give you more links and higher rankings in the search engines. Most bloggers knows the importance of getting links in order to get high rankings in search engines. But did you know that the best links are those that are natural recommendations? Additionally I experienced better rankings across all [...]

To improve the navigation of your users as well as search engine traffic and ranking to your WordPress blog I suggest making a good site map of your posts - a map of your site. A kind of user friendly archive of your posts. This is not “Google sitemap”! The benefits: The user can quickly find a [...]

How I rank on different keywords and links to the different SE queries.

home | site map

Articles



McDonalds | Bleach | Myspace Layouts | Personal Finance | Credit Cards