PHP4 Session cookie paths

From: Date: Fri, 30 Jun 2000 08:55:03 +0000
Subject: PHP4 Session cookie paths
Groups: php.general 
Request: Send a blank email to php-general+get-3985@lists.php.net to get a copy of this message
WARNING: list newbie. If I offend you in this message, please flame me gently :-) Hiya -- This may be a stupid question, but I've been searching the archives at MARC and haven't found any answer to my question. We have PHP running as a CGI under the Zeus web server, and I'm developing a user-validation and security system for our order process using PHP4 session management. The problem I'm having is that session IDs passed out by PHP are not recognized across directories (e.g., if the cookie is set when the log in on page <domain>/directory1, the session ID is NOT available in <domain>/directory2, and analysis of my cookie files has shown that this is because the cookies are including a path, despite being configured to use the "root" path. Has anybody else had this kind of problem? I have verified that the PHP.ini I'm using is actually being paid attention to by changing other variables. Here are the current session-related configuration values from php.ini: (I have changed some values for paranoid reasons) session.save_handler = "files" ; this shouldn't be used session.save_path = "/var/temp" ; not used for mySQL sessions, left blank session.name = "XXXourID" ; arbitrary, but should be human-readable for people with cookie warnings session.auto_start = 0 ; enabled session.lifetime = 0 ; signals "until the browser is closed" session.cookie_lifetime = 3000 ; session.cookie_path = / ; session.serialize_handler = "php" ; default, relates to how session_encode and session_decode work session.gc_probability = 1 ; until we get speed issues, garbage should always be cleaned up session.gc_maxlifetime = 3600 ; how many seconds should pass until data is seen as "garbage" and cleaned up? session.extern_referer_check = 0 ; session.entropy_file = "/dev/random" ; session.entropy_length = 1 ; entropy enabled session.use_cookies = 1 ; we want to use cookies if possible session.cookie_domain = "XXXourdomain" ; our domain register_globals = on ; I have already tried putting quotes around the "/". Any help appreciated! Seldo. -- Laurie Voss -- www.seldo.com laurievoss@email.com Jesus loves you. Everyone else thinks you're a jerk.

« previous php.general (#3985) next »