note 37235 deleted from security.globals by aidan

From: Date: Thu, 09 Sep 2004 09:16:40 +0000
Subject: note 37235 deleted from security.globals by aidan
References: 1  Groups: php.notes 
Request: Send a blank email to php-notes+get-76299@lists.php.net to get a copy of this message
Note Submitter: visionriver at yahoo dot com ---- This is a note for newbies to PHP - from one to another. Don't underestimate the important 'down the road' implications of register_globals on/off. It's quite fundamental and particularly in shared UNIX/Apache server environments. If you're working with register_globals ON (which it seems most hosting companies default to, due to the historic background of php) then you have session problems... you may not even be aware of them initially. If you're experiencing unanticipated responses from your application from time to time then these are very likely to be session related. Here's the lesson I recently learned the hard way: Turn register_globals OFF and don't even bother attempting to manage your php.ini settings through your php code. Create a .htaccess file in your document root that contains at least the following settings: 1. Set register_globals to off. 2. Load your fixed include paths. 3. Relocate your session file storage folder away from the default '/tmp' - including whatever garbage collection settings are appropriate for you. For all intents and purposes this is like inviting your real-life garbage collector into your home and asking them to decide what they think you should throw away today... Here's the .htaccess code: php_flag register_globals off php_value session.save_path /home/user/siteroot/sess/users php_value session.gc_maxlifetime xxx php_value include_path .:/home/user/siteroot.com/sess php_value auto_prepend /home/user/siteroot.com/sess/path_file.php Doing this has virtually eliminated all of my issues (PHP 4.2.3), which seemed to be piling up quite inexplicably. Right around the time you start thinking it's your hosting service provider - like when you start receiving the following: "Warning: Failed to write session data (files). Please verify that the current setting of session.save_path is correct (/somedir) in Unknown on line 0". That Unknown on Line 0 is Apache sending php/you a message to turn globals off and generally sort out your session management. Finally, trawling all of the php information/support sites you may be tempted to think that you can only get around your issues by installing your own session_handler. There's no need for that unless your site is handling massive volumes of traffic and you need database support. I tried that, but ran straight into the same problems again. PHP does the job very well. You just need to make sure that your session environment isn't contaminated and set your include paths before handing your user over to php. Bill

« previous php.notes (#76299) next »