RE: Sessions not propagated through different hosts - *Urgent!*
| From: | Nold, Mark | Date: | Fri, 14 Jul 2000 01:43:24 +0000 |
| Subject: | RE: Sessions not propagated through different hosts - *Urgent!* | ||
| Groups: | php.general | ||
| Request: | Send a blank email to php-general+get-6588@lists.php.net to get a copy of this message | ||
----------------------------------------------------------------------------
-----------------
Disclaimer: The information contained in this email is intended only for the
use of the person(s) to whom it is addressed and may be confidential or
contain legally privileged information. If you are not the intended
recipient you are hereby notified that any perusal, use, distribution,
copying or disclosure is strictly prohibited. If you have received this
email in error please immediately advise us by return email at
postmaster@normandy.com.au and delete the email document without making a
copy.
----------------------------------------------------------------------------
-----------------
Im planning to do something very similiar. Here is what i know.
1. If you are going with file based sessions, you must make those fiels
avaliable to both boxes. (ie: Share though NIS for un*x or SMB for NT). You
are probably better off in the long run doing this through a DB. (But hey
you can get this to work first). These files link the Session ID to various
session variable that you set.
2. The Session Id by default will be cookies. You need to make sure that a
both servers can see the same cookies this comes down to the cookie domain.
You will have to do some reading on this.
http://www.netscape.com/newsref/std/cookie_spec.html
What you will find is that "The default value of domain is the host name of
the server which generated the cookie response." This is more than likely
your problem.
mn
-----Original Message-----
From: Pedro Fonseca [mailto:pedro.fonseca@iscte.pt]
Sent: Thursday, July 13, 2000 8:07 PM
To: php-general@lists.php.net
Subject: Sessions not propagated through different hosts - *Urgent!*
Hi,
I posted a message here yesterday, regarding a problem with a site we are
developing. I will briefly describe the problem again:
We are using two different (physical) computers, each with its own apache
web server (and consequently each with its own php module). One of them is
SSL secured and the other is not. All the php files that need to be secured
(like client registration, contracts, personal information, etc) are on the
secured server; all the "normal" files (index.php, product catalogs, etc)
that need not to be secured are on the normal server.
When someone arrives at the site, index.php (that is on the non secured
server) is parsed and a session is created. After a user logs himself in,
he/she can access the secured files (i.e. can access he/she's personal
information, can buy images, etc). So, when a user (after logging in)
clicks the first file that is on the secured server, the login form
reapears like the user never got to loggin in the first place. So we have a
session that's created when a user arrives at the site and one other when
he accesses the secured files.
We tried to make both servers' session_save_path to /tmp of the non-secured
server but this did not work! Thus the problem is not derived from having
two different session_save_path (what about session.cookie_domain - what is
it for?). It seems that this happens because we are using two physical
different locations for the files, i.e. two different hosts. Wasn't this
not supposed to happen?, I mean weren't the files on the secured server
supposed to continue the session already created by the "normal" files?
Please, this is a very urgent problem we need to solve! Any help, ideas or
any contribution is much appreciated (thanks Chris Broussard and Jon Parise
for yesterday's tips, but we haven't solved the problem yet!)! If any PHP
language developers are reading this we would be very thankfull for your
attention!
Best regards,
Pedro Fonseca
/**
* pedro.fonseca@iscte.pt
* http://students.iscte.pt/~a17253/aminhapagina/
* Mobile: 96.459.835.7
*
**/