RE: [PHP4BETA] Docs for sessions?

From: Date: Thu, 22 Jul 1999 13:36:28 +0000
Subject: RE: [PHP4BETA] Docs for sessions?
References: 1  Groups: php.version4 
Request: Send a blank email to php-version4+get-2514@lists.php.net to get a copy of this message
-----Original Message----- From: Sascha Schumann [mailto:sascha@schumann.cx] Sent: 22 July 1999 12:13 To: Samuel Liddicott Cc: Matthew Clark; php4beta@lists.php.net Subject: Re: [PHP4BETA] Docs for sessions? >> Are you saying if cookies aren't supported it will use get mode? > >yes > >> One alternative is to have the session as part of the leading path >> >> http://my.domain/session-name=sessionid/index.html >> >> and let the server internally re-write the URL (without it). ALSO if a page >> is requested without a sid, but the referring page was from the same site >> with a sid, then a redirect to a URL including the SID is sent. > >well, that's nice. You can do this with the session module already. What? Really! Thats nice! Including use of http_referer to regenerate the missing sid? >> Thus a path-based session ID can be retained even without cookies, as long >> as a referer is sent (which most browsers do). >Do you have a sample configuration for Apache which shows how to >do that? We could add this to the documentation for interested >parties. Yep. The important features of this method are: 1) The session id is part of the document path and not a GET string so URL's do not need to be calculated to retain the session id (the browser effectively calculates it for RELATIVE LINKS). This means it works for static documents. 2) For ABSOLUTE links where the browser would loose the session ID, apache drags it back out of the http_referer and makes the client do a re-request. This means the path-based session ID is retained for static pages with relative or absolute links. and then Graphics and files which don't contain links (.gif/.jpg/.jpeg in this example) are treated specially so that 1) Absolute links to graphics don't do a redirect to plug-in the http_referer session id. 2) Relative links to graphics that DO have a session id have a redirect to a URL without so that cached copies can be used. warnings: Some browsers loose the referer for manually types links, so if the user changes the URL by hand, the session is gone. - but this is also likely with GET session id's. The apache rules below (use mod_rewrite) MUST be in the httpd.conf - I think this CANNOT be done in the .htaccess file. Note: if the leading path segment is like /....=..../ it is recognized as a session id/. For any script to obtain the session id is must look at the environment variable REQUEST_URI and extract it from there. I have used this method with PHPLIB as an alternative to the get fallback method (info at http://www.bigwig.net/phplib) # Maintaining session ID's in the URI path even for static pages with # absolute links # # by Sam Liddicott 1999 # # FIRST try and plug a session back in if we need it # we take the session from the http_referer # # 1. don't plug session back for gif or jpg as they are static & non-linking ReWriteCond %{REQUEST_URI} !(.gif|.jpg|.jpeg)$ # 2. check that there is not already a session id ReWriteCond %{REQUEST_URI} !/([^/=]*=[^/]*)/(.*) # 3. see if the referer had one ReWriteCond %{HTTP_REFERER} /([^/=]*=[^/]*)/(.*) # 4. if so plug session back in and re-request, stop processing (implied) ReWriteRule /(.*) /%1/$1 [R,L] # # SECOND to save time and bandwidth make then ask for non-linking items # directly, so they can get cached copy # 1. Is it a gif or jpeg? ReWriteCond %{REQUEST_URI} (.gif|.jpg|.jpeg)$ # 2. Then redirect without session-id so they get cached copies RewriteRule /([^/=]*=[^/]*)/(.*) /$2 [R,L] # # THIRD we have a session ID, rewrite internally to map to file structure RewriteRule /([^/=]*=[^/]*)/(.*) /$2 # # and thats it Sam

« previous php.version4 (#2514) next »