Re: Search Engines and Sessions(Cross Posted to comp.lang.php)
| From: | JJ Harrison | Date: | Sun, 21 Jul 2002 07:31:21 +0000 |
| Subject: | Re: Search Engines and Sessions(Cross Posted to comp.lang.php) | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-108711@lists.php.net to get a copy of this message | ||
I just had an idea.
session_start();
// Start Sessions
if(isset($_SESSION['fname']) != true){
session_destroy();
}
It works until I login. Then I get this error(When cookies is on):
Warning: Trying to destroy uninitialized session in C:\Inetpub\CO2 Busters
MK2\includes\required.php on line 35
Warning: Cannot send session cookie - headers already sent by (output
started at C:\Inetpub\CO2 Busters MK2\includes\article.func.php:148) in
C:\Inetpub\CO2 Busters MK2\includes\session.func.php on line 13
Warning: Cannot send session cache limiter - headers already sent (output
started at C:\Inetpub\CO2 Busters MK2\includes\article.func.php:148) in
C:\Inetpub\CO2 Busters MK2\includes\session.func.php on line 13
Or this error(When cookies are off):
Warning: Cannot send session cookie - headers already sent by (output
started at C:\Inetpub\CO2 Busters MK2\includes\article.func.php:148) in
C:\Inetpub\CO2 Busters MK2\includes\session.func.php on line 22
Warning: Constant sid already defined in C:\Inetpub\CO2 Busters
MK2\includes\session.func.php on line 22
Warning: Cannot send session cache limiter - headers already sent (output
started at C:\Inetpub\CO2 Busters MK2\includes\article.func.php:148) in
C:\Inetpub\CO2 Busters MK2\includes\session.func.php on line 22
Here is the session.func.php file:
<?
function welcome_or_login(){
if(isset($_SESSION['fname'])){
echo 'Hello '.$_SESSION['fname'].'.';
} else {
do_h('Login', 3, 'y');
do_hr();
login_form('');
}
}
function register_in_session($uid, $gid, $banid, $username, $fname, $lname,
$email){
// Used in conjuction with validate() to input user info into the session
session_register('uid');
session_register('gid');
session_register('banid');
session_register('username');
session_register('fname');
session_register('lname');
session_register('email');
}
?>
when I do a var_dump($_SESSION) on the logon page(after logging in) I get
array(0) { }
when I do the same thing on any other page I get this:
array(7) { ["uid"]=> &string(1) "1" ["gid"]=> &string(1)
"1" ["banid"]=>
&string(1) "0" ["username"]=> &string(6) "Lizner"
["fname"]=> &string(2)
"JJ" ["lname"]=> &string(8) "Harrison" ["email"]=>
&string(24)
"webmaster@co2busters.org" }
How can I fix it? or isn't it possible?
--
JJ Harrison
webmaster@tececo.com
www.tececo.com
Once I leave the login page the sessions work fine(I did a var dump
"Richard Lynch" <rich@phpbootcamp.com> wrote in message
news:php.general-108706@news.php.net...
> >I am worried about search engines and sessions.
> >
> >If the UA doesn't support cookies the session id is passed through the
urls.
> >
> >Search engines won't spider pages with a ? in the url because
> >page.php?sid=bdf4f91bcc71443cd251a7d3eed05c9c and
> >page.php?sid=5a547f86ea14186942d0305e352d9e41 would be considered
different
> >pages(The search engines robot could go into a continuos loop).
> >
> >I only use sessions on all pages but they do nothing if the user hasn't
> >signed in.
> >
> >what would be a good way to not start the session id in the url if the
> >person had not logged in anyway? The problem is that if you haven't
started
> >a session you can't check for session variables.
>
> You have several options:
>
> 1. Use robots.txt (Google for Robot Guidelines) to "force" the search
> engines to specific URLs you want indexed.
>
> 2. Attempt to "detect" the major search engines, and give them a
sessionless
> link. Not recommended. They may think you're trying to hide a porn site
> from them.
>
> 3. "Hide" the ? from the search engines, by simply not using ? in your
URL.
> Use / instead, and then your GET data won't be in $_GET, but it will be in
> $PATH_INFO and $REQUEST_URI (see <?php phpinfo();?>. It will also mess up
> $PHP_SELF, but it's a small price to pay. :-)
> php.php/sid/bdf4f91bcc71443cd251a7d3eed05c9c
>
> While these will be "different" pages to the search engines, you should be
> propagating the session ID for the entire search -- IE< the spider will
get
> its own SID, and will keep re-presenting it in the links it continues to
> traverse. Although, if you time out your sessions faster than the spider
> travels, you'll lose them.
>
> There are probably more ways to skin this cat.
>
> --
> Like Music? http://l-i-e.com/artists.htm
>