RE: [PHP] Problems with Cookies / Sessions

From: Date: Mon, 11 Sep 2000 03:04:10 +0000
Subject: RE: [PHP] Problems with Cookies / Sessions
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-16111@lists.php.net to get a copy of this message
How are you reading the cookies? HTTP_COOKIE_VARS? I noticed you said you are using PHP4.0.2 - apparently there is a problem with that release. The somehow changed HTTP_COOKIE_VARS to HTTP_SERVER_VARS. Here is a copy of the email: > -----Original Message----- > From: Feroze Md. Arif [mailto:feroze_arif@pacific.net.sg] > Sent: Monday, 11 September 2000 13:01 > To: php-general@lists.php.net > Subject: [PHP] Problems with Cookies / Sessions > > > Hi, > > I am trying to keep track of user sessions using cookies and am facing a > peculiar problem. Here is what I am doing: > > 1. When my user logs in using a user id and password, I use a script to > check if cookies are enabled on her machine. The script is a > simple script > that sets a cookie and checks if it is readable upon reloading itself. If > cookies are enabled then I use the header function to take the user to a > authentication script (header("Location: $page")). > > 2. In the authentication script I check if the userid / password > combination > is legal. If the combination is legal then I generate the > sessionid, write > the sessionid, user_id and logged time into a mysql database and > then I set > two cookies. setcookie("login_id", $user_id), > setcookie("cookie_session_id", $sessionid). Then I use the > header function > to take the user to the actual system. > > 3. In the system every page checks if the user has been > authenticated. Here > the script just reads the cookie_session_id and checks if this id is > available in the mysql database (select * from sessiontable where > sessionid > = $cookie_session_id). If the session is valid, then I check to see the > loggedtime to see if the session has been unused for a specific period of > time. If the session time has been exceeded then a session > invalid message > is displayed and the user is asked to login again. If the > session is valid > I just update the loggedtime to current time and then display whatever the > user has requested. > > 4. Upon logout I just clear the cookies with > setcookie("cookie_session_id") > and setcookie("login_id"). > > Now my problem is that whenever a user logs into the system for the first > time, she gets either a cookies not enabled message or when she tries to > access any function in the system she gets the "session invalid message". > This happens only once at the beginning. Once she logs in again > everything > works fine. What am I doing wrong? and why I am getting this peculiar > behaviour? I would appreciate it very much if any one can throw > some light > on this. > > Looking forward to your advice / help. > > In a daze > Feroze > > P.S. I am aware that the order in which cookies are set / > destroyed should > be in the reverse in PHP3.0, I am using PHP4.02 and just to be > sure I do not > delete and set cookies in the same page. > > > -- > PHP General Mailing List (http://www.php.net/) > To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net > For additional commands, e-mail: php-general-help@lists.php.net > To contact the list administrators, e-mail: php-list-admin@lists.php.net >

« previous php.general (#16111) next »