in reply to Expiring password after a time limit has elapsed

On a low traffic website I wrote, I check the expiry of the sessions / passwords with every hit BEFORE I do anything else. It is a simple SQL-command to delete all session /password info which are past their "sell by" date. It does not seem to slow-down noticeably the site.

CountZero

A program should be light and agile, its subroutines connected like a string of pearls. The spirit and intent of the program should be retained throughout. There should be neither too little or too much, neither needless loops nor useless variables, neither lack of structure nor overwhelming rigidity." - The Tao of Programming, 4.1 - Geoffrey James

  • Comment on Re: Expiring password after a time limit has elapsed