PHP4 Session cookie paths
| From: | Laurie Voss | Date: | Fri, 30 Jun 2000 08:55:03 +0000 |
| Subject: | PHP4 Session cookie paths | ||
| Groups: | php.general | ||
| Request: | Send a blank email to php-general+get-3985@lists.php.net to get a copy of this message | ||
WARNING: list newbie. If I offend you in this message, please flame me
gently :-)
Hiya --
This may be a stupid question, but I've been searching the
archives at MARC and haven't found any answer to my question.
We have PHP running as a CGI under the Zeus web server, and I'm
developing a user-validation and security system for our order process
using PHP4 session management. The problem I'm having is that session
IDs passed out by PHP are not recognized across directories (e.g., if
the cookie is set when the log in on page <domain>/directory1, the
session ID is NOT available in <domain>/directory2, and analysis of my
cookie files has shown that this is because the cookies are including
a path, despite being configured to use the "root" path.
Has anybody else had this kind of problem? I have verified that the
PHP.ini I'm using is actually being paid attention to by changing
other variables. Here are the current session-related configuration
values from php.ini:
(I have changed some values for paranoid reasons)
session.save_handler = "files" ; this shouldn't be used
session.save_path = "/var/temp" ; not used for mySQL sessions,
left blank
session.name = "XXXourID" ; arbitrary, but should be human-readable for
people with cookie warnings
session.auto_start = 0 ; enabled
session.lifetime = 0 ; signals "until the browser is closed"
session.cookie_lifetime = 3000 ;
session.cookie_path = / ;
session.serialize_handler = "php" ; default, relates to how session_encode
and session_decode work
session.gc_probability = 1 ; until we get speed issues, garbage should always
be cleaned up
session.gc_maxlifetime = 3600 ; how many seconds should pass until data is seen as
"garbage" and cleaned up?
session.extern_referer_check = 0 ;
session.entropy_file = "/dev/random" ;
session.entropy_length = 1 ; entropy enabled
session.use_cookies = 1 ; we want to use cookies if possible
session.cookie_domain = "XXXourdomain" ; our domain
register_globals = on ;
I have already tried putting quotes around the "/".
Any help appreciated!
Seldo.
--
Laurie Voss -- www.seldo.com
laurievoss@email.com
Jesus loves you. Everyone else thinks you're a jerk.