note 37235 deleted from security.globals by aidan
| From: | aidan@php.net | Date: | Thu, 09 Sep 2004 09:16:40 +0000 |
| Subject: | note 37235 deleted from security.globals by aidan | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-76299@lists.php.net to get a copy of this message | ||
Note Submitter: visionriver at yahoo dot com
----
This is a note for newbies to PHP - from one to another. Don't underestimate the important
'down the road' implications of register_globals on/off. It's quite fundamental and
particularly in shared UNIX/Apache server environments. If you're working with register_globals
ON (which it seems most hosting companies default to, due to the historic background of php) then
you have session problems... you may not even be aware of them initially. If you're
experiencing unanticipated responses from your application from time to time then these are very
likely to be session related.
Here's the lesson I recently learned the hard way: Turn register_globals OFF and don't
even bother attempting to manage your php.ini settings through your php code. Create a .htaccess
file in your document root that contains at least the following settings:
1. Set register_globals to off.
2. Load your fixed include paths.
3. Relocate your session file storage folder away from the default '/tmp' - including
whatever garbage collection settings are appropriate for you. For all intents and purposes this is
like inviting your real-life garbage collector into your home and asking them to decide what they
think you should throw away today...
Here's the .htaccess code:
php_flag register_globals off
php_value session.save_path /home/user/siteroot/sess/users
php_value session.gc_maxlifetime xxx
php_value include_path .:/home/user/siteroot.com/sess
php_value auto_prepend /home/user/siteroot.com/sess/path_file.php
Doing this has virtually eliminated all of my issues (PHP 4.2.3), which seemed to be piling up quite
inexplicably. Right around the time you start thinking it's your hosting service provider -
like when you start receiving the following: "Warning: Failed to write session data (files).
Please verify that the current setting of session.save_path is correct (/somedir) in Unknown on line
0". That Unknown on Line 0 is Apache sending php/you a message to turn globals off and
generally sort out your session management.
Finally, trawling all of the php information/support sites you may be tempted to think that you can
only get around your issues by installing your own session_handler. There's no need for that
unless your site is handling massive volumes of traffic and you need database support. I tried that,
but ran straight into the same problems again. PHP does the job very well. You just need to make
sure that your session environment isn't contaminated and set your include paths before handing
your user over to php.
Bill