Bug #15158 Updated: Session get replaced when moving to other domain

From: Date: Mon, 04 Feb 2002 00:41:18 +0000
Subject: Bug #15158 Updated: Session get replaced when moving to other domain
References: 1  Groups: php.dev 
Request: Send a blank email to php-dev+get-79004@lists.php.net to get a copy of this message
ID: 15158 Updated by: yohgaki@php.net Reported By: miki@canaan.co.il -Status: Open +Status: Bogus Bug Type: Session related Operating System: RH7.1 PHP Version: 4.1.1 New Comment: Cookie will not be sent if domain is changed. = NOT a bug. (If it does, it's serious privacy flaw... ) If you are interested in cross domain session, phpbuilder.com had an article about it. Previous Comments: ------------------------------------------------------------------------ [2002-01-22 05:34:17] miki@canaan.co.il in My 4.0.6 php.ini cookie_domain = in My 4.1.1 php.ini cookie_domain = Worked very well through all the 4.0.x ver untill the 4.1.1 ( didnt checked the 4.1.0 ) ------------------------------------------------------------------------ [2002-01-22 05:24:20] jan@php.net Please check your session.cookie_domain setting (php.ini directive). ------------------------------------------------------------------------ [2002-01-22 05:17:40] miki@canaan.co.il When I move from www.domain.com to secure.domain.com with the PHPSESID in the URL the session from the previous domain continue to work in the new one until the first inner link that does not have the PHPSESID is clicked. When such link is clicked ( or submitted ) the session_start/register initiate new session to the domain and forget about the old session. This behavior started after I upgraded to 4.1.1 from 4.0.6. IMHO In 4.0.6 the session was accepted for the domain ( as default ) after PHPSESID was delivered but in 4.1.1 its not. ------------------------------------------------------------------------ -- Edit this bug report at http://bugs.php.net/?id=15158&edit=1

« previous php.dev (#79004) next »