note 33290 deleted from function.session-start by peehaa
| From: | peehaa@php.net | Date: | Fri, 09 Dec 2016 21:59:51 +0000 |
| Subject: | note 33290 deleted from function.session-start by peehaa | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-208313@lists.php.net to get a copy of this message | ||
Note Submitter: gadgetguy03 at lycos dot com
----
SESSION LOST ON HEADER REDIRECT (CGI on IIS 5.0)
I realize there are numerous scattered posts on this issue, but I would like to add my 2¢ since it
took me a whole day and a download of the LiveHTTPHeaders Mozilla plugin to figure it out.
On the **CGI** version of PHP on IIS 5.0/Windows 2000, the following code will not work as expected:
/***** sess1.php *****/
session_start();
$_SESSION["key1"] = "testvalue";
header("Location: sess2.php");
/***** sess2.php *****/
session_start();
echo "key1 = '".$_SESSION["key1"]."'";
PROBLEM:
All session data is lost after a header redirect from the first page on which the session is
initialized. The problem is, the PHPSESSID cookie is not being sent to the browser (ANY browser, IE
or Mozilla) on the initial session page with the header("Location: ...") redirect. This is
unrelated to client cookie settings - the set-cookie: header just isn't sent.
SOLUTION:
I was able to remedy the problem by switching to the ISAPI DLL version. This seems to be an MS/IIS
bug, NOT a PHP bug - go figure. I hope this saves you some headaches especially with your user
authentication scripts!!
The closest matching "bug" report I found:
http://bugs.php.net/bug.php?id=14636