Session ids lost on a 5th page
| From: | Dan Kalowsky | Date: | Wed, 01 Nov 2000 14:56:06 +0000 |
| Subject: | Session ids lost on a 5th page | ||
| Groups: | php.dev | ||
| Request: | Send a blank email to php-dev+get-36654@lists.php.net to get a copy of this message | ||
Using a cvs build from about... 20 minutes ago (9:00 AM EST).
OS is FreeBSD 4.1.1-Release
gcc version 2.95.2 19991024 (release)
Currently have a series of pages that rely upon data being set on a
first page, and run through and modified on each page thereafter. Its a
fairly large setup...on the 5th page though, the session id is not found
by PHP, and a new one is assigned. The system is set to use cookies.
The document root on the machine works like this: /usr/local/www/data
with the following underlying directories:
Login
home
setup
include
weather
error
images
js
Upon initial login, the user starts in the 'Login' directory and
dependent upon if some of their information is found, they are
redirected to a series of pages in the 'setup' directory (to add the
information), or to the 'home' directory. In the case of data not
found, the user is over to the 'setup' directories just fine, but upon
the 5th page the session id is lost. The follow this series of steps
looks something like so:
Login/login_redirect.php
|
(initial session id created here)
|
+--->setup/new_settop_redirect.php
|
+--> setup/setup_add_select_lang.php
|
+--> setup/setup_legal_disclaimer.php
|
(new session id created here)
|
+--> setup/new_settop_redirect.php
|
+--> setup/setup_add_settop.php
Fortunately or unfortunately the new id does not seem to change again,
but I am unable to test further than one page as it redirects to an
error page, and ends the user add process.
In the case of already having this user data, the session Id is lost
immediately after the login_redirect.php
Because this system is going to potentially be used in our Internet TV
system, we have a customized browser (NTSC/PAL don't exactly like
standard Netscape), and I haven't discounted that the browser can be
losing the cookie, although I'm told this is extremely unlikely. In an
effort to further help understand whats happening in this process, I've
added in a series of php_error statements to the session.c under the
session_start function. Basically to get a feeling of the flow of php
session creation, and to have both php state when its creating a new
session, and our browser to display what cookies it has at each
request.
At one location I have placed two php_error statements (using E_WARNING)
next to each other, and the result is only one is ever printed (the
first).
The change done to the session.c are found below, area of interest
marked with a "+>" :
static void php_session_start(PSLS_D)
{
pval **ppid;
pval **data;
char *p;
int send_cookie = 1;
int define_sid = 1;
int module_number = PS(module_number);
int nrand;
int lensess;
ELS_FETCH();
php_error(E_WARNING, "php_session_start: entered function");
if (PS(nr_open_sessions) != 0)
return;
lensess = strlen(PS(session_name));
/*
* Cookies are preferred, because initially
* cookie and get variables will be available.
*/
if (!PS(id)) {
+> php_error(E_WARNING, "php_session_start: no current id
found");
+> php_error(E_WARNING, "php_session_start; searching cookie
vars");
if (zend_hash_find(&EG(symbol_table), "HTTP_COOKIE_VARS",
sizeof("HTTP_COOKIE_VARS"), (void **) &data) ==
SUCCESS &&
Z_TYPE_PP(data) == IS_ARRAY &&
zend_hash_find(Z_ARRVAL_PP(data), PS(session_name),
lensess + 1, (void **) &ppid) == SUCCESS) {
PPID2SID;
define_sid = 0;
send_cookie = 0;
php_error(E_WARNING, "php_session_start; found cookie var
%s",PS(id));
}
<...snip...>
A copy of the output to the php-error.log file is found here:
<errorentry>
<datetime>01-11-2000 09:44:37 (EST)</datetime>
<errornum>2</errornum>
<errortype>Warning</errortype>
<errormsg>php_session_start: entered function</errormsg>
<scriptname>/usr/local/www/data/Login/login_redirect.php</scriptname>
<scriptlinenum>31</scriptlinenum>
</errorentry>
<errorentry>
<datetime>01-11-2000 09:44:37 (EST)</datetime>
<errornum>2</errornum>
<errortype>Warning</errortype>
<errormsg>php_session_start: no current id found</errormsg>
<scriptname>/usr/local/www/data/Login/login_redirect.php</scriptname>
<scriptlinenum>31</scriptlinenum>
</errorentry>
<errorentry>
<datetime>01-11-2000 09:44:37 (EST)</datetime>
<errornum>2</errornum>
<errortype>Warning</errortype>
<errormsg>php_session_start: its a valid page request, generate
a new id for it</errormsg>
<scriptname>/usr/local/www/data/Login/login_redirect.php</scriptname>
<scriptlinenum>31</scriptlinenum>
</errorentry>
From the flow print out above, it seems as if php_error #3 is never
printed, despite being placed IMMEDIATELY after php_error #2... no
conditionals between it. I have built this, made it clean, rebuilt it,
and even tried pulling down a cvs build from scratch and re-adding my
changes. This has happened on each try, and the question is why?
If anyone out there can help me understand why this session id is being
lost on the 5th page, I would appriciate it greatly. Or if you can even
explain why the third php_error is never printed, that would hopefully
help me further understand what is happening to the session id.
Regardless thanks for reading this far!
A copy of the php.ini file session section:
[Session]
session.save_handler = files ; handler used to store/retrieve
data
session.save_path = /tmp ; argument passed to save_handler
; in the case of files, this is the
; path where data files are stored
session.use_cookies = 1
session.name = TICS
session.auto_start = 0 ; initialize session on request
startup
session.cookie_lifetime = 0 ; lifetime in seconds of cookie
; or if 0, until browser is
restarted
session.cookie_path = / ; the path the cookie is valid for
session.cookie_domain = ; the domain the cookie is valid for
session.serialize_handler = php ; handler used to serialize data
; php is the standard serializer of
PHP
session.gc_probability = 1 ; percentual probability that the
; 'garbage collection' process is
started
; on every session initialization
session.gc_maxlifetime = 1440 ; after this number of seconds,
stored
; data will be seen as 'garbage' and
; cleaned up by the gc process
session.referer_check =
session.entropy_length = 16
session.entropy_file = /dev/urandom
session.cache_limiter = nocache ; set to {nocache,private,public} to
session.cache_expire = 180
A copy of the configure options:
./configure --with-imap \
--with-gettext \
--with-pgsql \
--enable-debug \
--enable-debugger \
--enable-snmp \
--enable-track-vars \
--enable-trans-sid \
--with-gd=/usr/local \
--with-apxs=/usr/local/sbin/apxs \
--disable-magic-quotes \
--enable-short-tags \
--without-mysql \
--without-tsrm-pthreads \
--enable-wddx \
--prefix=/suproot/usr/local
--
Dan Kalowsky "Tonight I think I'll walk alone,
Worldgate Communications I'll find my soul as I go home."
Software Engineer - TICS Group - Temptation