note 31603 deleted from function.session-start by tomsommer

From: Date: Sat, 28 Aug 2004 22:59:34 +0000
Subject: note 31603 deleted from function.session-start by tomsommer
References: 1  Groups: php.notes 
Request: Send a blank email to php-notes+get-75516@lists.php.net to get a copy of this message
Note Submitter: gmgiles at pacbell dot net ---- Regarding client-side cookies, session_start(), and browser privacy settings: if you use custom login session/validation code for your website, and find that users are unable to login with valid username/password, their browser privacy settings may be to blame - their browser is likely blocking client-side cookie creation. Internet Explorer's "Medium-High" privacy level (and higher) can block client-side cookies, and if your session verification code relies on checking a session variable before displaying a page (i.e.: $_SESSION[user_name]), the verification code might not behave as you expect it to. Unfortunately, session_start() always returns TRUE whether the client cookie was created or not, so you'll need to roll your own error checking code. The following is simplified excerpt from the custom verifySession() function I call at the top of each page; this snippet should give you a rough idea for your own error checking... /* example start */ session_start(); // check to see if session exists // assumes $_SESSION[user_name] was previously defined by your custom login validation code switch (isset($_SESSION[user_name])) { case TRUE: // Client cookie was probably created. echo 'Session verified.'; break; case FALSE: // Client cookie either doesn't exist or wasn't created. // Browser privacy setting may be set too high. echo 'Verificiation FAILED!'; break; } /* example end */ I suggest that if you require client-side cookies to allow logins, simply mention that fact immediately above your login prompt. Tailor the above code to your own specific site design. YMMV.

« previous php.notes (#75516) next »