note 35231 added to ref.session
| From: | eki at sonet dot net dot au | Date: | Sun, 24 Aug 2003 15:10:12 +0000 |
| Subject: | note 35231 added to ref.session | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-54990@lists.php.net to get a copy of this message | ||
As per Conny's experience below, I believe the issue is related to how Session is stored using
Cookie.
...
(ie, user surfs to server.foo.bar/login.php which authenticates and redirects to
x.y.z.w/nextpage.php).
...
The user agent will only send its previously stored Cookie related to the Session if the domain name
of the requesting server matches with that of stored in the Cookie.
As a result, redirecting the Session to x.y.z.w/nextpage.php instead of server.foo.bar/nextpage.php
certainly prevents the user agent to send its Cookie data relating to the Session.
In conclusion, the moral of the story is to always make sure that in your Web Application using
Cookie, you use the domain name and include it within setcookie() parameter. Make sure that the
ServerName directive points to the same resolvable FQDN to avoid using IP address.
----
Manual Page -- http://www.php.net/manual/en/ref.session.php
Edit Note -- http://master.php.net/manage/user-notes.php?action=edit+35231
Delete Note -- http://master.php.net/manage/user-notes.php?action=delete+35231&report=yes
Reject Note -- http://master.php.net/manage/user-notes.php?action=reject+35231&report=yes