PHP session lessons lost on directory change?

I have a simple login system using PHP sessions, but more recently it seems that if you visit pages not in a specific directory (/ login /), you will always be marked as not logged in, even if you are. It looks like my session data is lost when changing directories (e.g. / login / user /).

I don't think I touched on the code myself since there was a problem, is there something my web host could do with my PHP installation that would delete the session data and is there a workaround?

EDIT:
Inside each file that needs authorization, a loginfunctions.php file is loaded which calls session_start () and validates the login. The files that work in / login and I copy and paste in / login / user stop working, although I update all the relevant paths and links.

EDIT2: Ok, code.

On the real pages that are giving me the error it is auth. the code:

require_once("../../../includes/loginFunctions.php");

$login = new login; 
$login->checkLogin(0);

      

Inside loginFunctions.php:

class login{

    function checkLogin($requiredAccess){

            session_start();

            if($_SESSION['accesslevel'] < $requiredAccess || $_SESSION['logged_in'] != TRUE){
                die("You don't have access to this area. If you should have access, please log in again. <a href='/login/'>Login</a>");
            }

            if (isset($_SESSION['HTTP_USER_AGENT'])){
                if ($_SESSION['HTTP_USER_AGENT'] != md5($_SERVER['HTTP_USER_AGENT'])){
                    session_destroy();
                    die("Bad session. Please log in again. <a href='/login/'>Login</a> ");
                }
            } else {
                $_SESSION['HTTP_USER_AGENT'] = md5($_SERVER['HTTP_USER_AGENT']);
            }

            if (!isset($_SESSION['initiated'])){
                session_regenerate_id();
                $_SESSION['initiated'] = true;
            }

    }

}

      

The $ requiredAccess variable is the access level you need to access this page, so if you have access level 3 in the database, you can view levels 0, 1, 2, and 3 of the page. This is specified when the function is called on the main page and compared to the current user's access level, which is defined in $ _SESSIONS at login.

I get the error "You do not have access to this area, etc." when I try to access these pages. If I try to print the $ _SESSION variables, nothing is displayed, they appear to be empty. If I move the file to the / login / folder (one level up) and update the links, they work fine and all the variables are printed out fine. This leads me to think that the code is not the part that is not working, but some setting in my PHP installation that was changed without my notice.

+2


a source to share


6 answers


Perhaps you are not calling session_start () when begging for pages not in / login / ..?



+2


a source


I had a similar problem. Make sure you don't have a php.ini file. Removing this issue fixed the issue. And yet, looking exactly why. The php.ini file might even be empty and it will stop transferring session data to multiple directories ...



+1


a source


They may have changed the php.ini setting of session.cookie_path .

You must call session-set-cookie-params before you call session_start

and make sure you set the cookie path yourself. Install it in the highest level directory for which you want the session to be valid. EG, if you set it to /login

, it will be valid for /login

and /login/user

. If you want your session to be valid for etire site set path/

0


a source


I had a similar problem. you can use:  <? setcookie("TestCookie", $value, time()+3600, "/~rasmus/", ".example.com", 1); ?>

or something similar. I know the cookie and session variables are the other desired solution, but that allowed me to solve my problem.

See documentation here

0


a source


Make sure you have the same file php.ini

in every directory from which you want to access session variables.

0


a source


This is why you shouldn't use a directory to create friendly urls ...

Remember to call session_start () every time you need a session.

-1


a source







All Articles