Re: cookie problems

From: Date: Sun, 06 Aug 2000 05:58:17 +0000
Subject: Re: cookie problems
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-10306@lists.php.net to get a copy of this message
clay bond wrote:
The obvious solution was for us to set a cookie when they login. When they go to the gradebook server, the app can read the cookie and authenticate them. Here's what we've done (php is installed as a cgi wrapper on the univ server): #!/usr/local/bin/php3 setcookie("tuna",$REMOTE_USER,time()+3600);
You've left out the path, domain, and secure arguments. From the manual: "All the arguments except the name argument are optional. If only the name argument is present, the cookie by that name will be deleted from the remote client. You may also replace any argument with an empty string ("") in order to skip that argument. The expire and secure arguments are integers and cannot be skipped with an empty string. Use a zero (0) instead." So if your server is www.server.com, then you need: setcookie('tuna', $REMOTE_USER, time()+3600,
          '/', 'www.server.com', 0);
The 4th argument above, the path, will allow the cookie to be set and retrieved from any path/location on www.server.com over an non-secure (SSL) connection.
The major problem is that no cookie is being written to the hard drive. So we added the expiry above, but still no cookie on the drive. Why not?
I suspect that this is only the case with some browsers. From the manual: "Microsoft Internet Explorer 4 with Service Pack 1 applied does not correctly deal with cookies that have their path parameter set. Netscape Communicator 4.05 and Microsoft Internet Explorer 3.x appear to handle cookies incorrectly when the path and time are not set." That is from my older copy of the manual. You may want to check here, as well as read the user comments: http://www.php.net/manual/function.setcookie.php
The minor problem is that we want the cookie to be passed no matter what domain the client is. Many of our students either use a local ISP (not the univ), and now that cable modem service is available, more and more students will have that. If we leave out the domain, it defaults to the same as the server. How can we specify that the cookie is to be passed no matter where the connection is from?
'Domain' isn't referring to the client-side (Ie. not the users' IP addresses or resolved host names), if that's what you mean. The domain argument for setcookie() should be the server the cookie is being sent from. Further, two different domains cannot share cookies. http://www.netscape.com/newsref/std/cookie_spec.html. Brian

« previous php.general (#10306) next »