Solved

PHP session variable & PHPSESSID

Posted on 2004-08-24
7
321 Views
Last Modified: 2008-03-17
Hi all, I am having an error in getting the session variable in php:

1. my application is a login page, if user successfully logged in, the user id will become sessioned and then he will be directed to the main page. I don't know why there are "?PHPSESSID=xxxxxxxx" in all URL of the main page...

I have tried some similar application in another server, but the PHPSESSID should not be shown... how can I make this invisible??

2. in each of the main page link, I redirect the user to a frame page, but it seems that the frameset cannot get the sessioned variable....I can only get the variable if I open another browser at the same time and login again...(in this double login case, I will not get "?PHPSESSID=xxxxxxxx" at the end of the main page link)

Hope someone can help, thanks
0
Comment
Question by:esther_6694
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
  • 2
7 Comments
 
LVL 18

Accepted Solution

by:
CrYpTiC_MauleR earned 75 total points
ID: 11879900
0
 
LVL 18

Expert Comment

by:CrYpTiC_MauleR
ID: 11879909
what it does is it appends the session variable to each hyperlink ti see on the page. You can disable that for hyperlinks or you can switch to having session via cookies which dont require the session to be passed via anu URlL.

Regards,
Nick
0
 
LVL 48

Assisted Solution

by:hernst42
hernst42 earned 75 total points
ID: 11879915
it looks like the session.use_trans_sid is enabled on your system. Then PHP adds that part if no cookie can be set.

; trans sid support is disabled by default.
; Use of trans sid may risk your users security.
; Use this option with caution.
; - User may send URL contains active session ID
;   to other person via. email/irc/etc.
; - URL that contains active session ID may be stored
;   in publically accessible computer.
; - User may access your site with the same session ID
;   always using URL stored in browser's history or bookmarks.
session.use_trans_sid = 0

So disable session.use_trans_sid if it is enabled.
0
 
LVL 48

Expert Comment

by:hernst42
ID: 12531434
splitpoints CrYpTiC_MauleR and hernst42
0

Featured Post

Why Off-Site Backups Are The Only Way To Go

You are probably backing up your data—but how and where? Ransomware is on the rise and there are variants that specifically target backups. Read on to discover why off-site is the way to go.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Popularity Can Be Measured Sometimes we deal with questions of popularity, and we need a way to collect opinions from our clients.  This article shows a simple teaching example of how we might elect a favorite color by letting our clients vote for …
Part of the Global Positioning System A geocode (https://developers.google.com/maps/documentation/geocoding/) is the major subset of a GPS coordinate (http://en.wikipedia.org/wiki/Global_Positioning_System), the other parts being the altitude and t…
Explain concepts important to validation of email addresses with regular expressions. Applies to most languages/tools that uses regular expressions. Consider email address RFCs: Look at HTML5 form input element (with type=email) regex pattern: T…
This tutorial will teach you the core code needed to finalize the addition of a watermark to your image. The viewer will use a small PHP class to learn and create a watermark.

630 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question