note 31603 deleted from function.session-start by tomsommer
| From: | tomsommer@php.net | Date: | Sat, 28 Aug 2004 22:59:34 +0000 |
| Subject: | note 31603 deleted from function.session-start by tomsommer | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-75516@lists.php.net to get a copy of this message | ||
Note Submitter: gmgiles at pacbell dot net
----
Regarding client-side cookies, session_start(), and browser privacy settings: if you use custom
login session/validation code for your website, and find that users are unable to login with valid
username/password, their browser privacy settings may be to blame - their browser is likely blocking
client-side cookie creation.
Internet Explorer's "Medium-High" privacy level (and higher) can block client-side
cookies, and if your session verification code relies on checking a session variable before
displaying a page (i.e.: $_SESSION[user_name]), the verification code might not behave as you expect
it to.
Unfortunately, session_start() always returns TRUE whether the client cookie was created or not, so
you'll need to roll your own error checking code. The following is simplified excerpt from the
custom verifySession() function I call at the top of each page; this snippet should give you a rough
idea for your own error checking...
/* example start */
session_start();
// check to see if session exists
// assumes $_SESSION[user_name] was previously defined by your custom login validation code
switch (isset($_SESSION[user_name])) {
case TRUE:
// Client cookie was probably created.
echo 'Session verified.';
break;
case FALSE:
// Client cookie either doesn't exist or wasn't created.
// Browser privacy setting may be set too high.
echo 'Verificiation FAILED!';
break;
}
/* example end */
I suggest that if you require client-side cookies to allow logins, simply mention that fact
immediately above your login prompt. Tailor the above code to your own specific site design. YMMV.