note 35231 deleted from ref.session by vincent
| From: | vincent@php.net | Date: | Sun, 24 Aug 2003 18:06:29 +0000 |
| Subject: | note 35231 deleted from ref.session by vincent | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-55004@lists.php.net to get a copy of this message | ||
Note Submitter: eki@sonet.net.au
----
As per Conny's experience below, I believe the issue is related to how Session is stored using
Cookie.
...
(ie, user surfs to server.foo.bar/login.php which authenticates and redirects to
x.y.z.w/nextpage.php).
...
The user agent will only send its previously stored Cookie related to the Session if the domain name
of the requesting server matches with that of stored in the Cookie.
As a result, redirecting the Session to x.y.z.w/nextpage.php instead of server.foo.bar/nextpage.php
certainly prevents the user agent to send its Cookie data relating to the Session.
In conclusion, the moral of the story is to always make sure that in your Web Application using
Cookie, you use the domain name and include it within setcookie() parameter. Make sure that the
ServerName directive points to the same resolvable FQDN to avoid using IP address.