Solved

Problem with session data across subdomains and protocols

Posted on 2004-09-22
3
3,236 Views
Last Modified: 2012-06-27
Ready for this one, everyone?

I'm having a problem accessing a PHP session across subdomains.

I have a Linux/Apache server running PHP 4.3.2 with one domain on it. Let's call it foo.com. The domain has the usual 'www' subdomain plus another subdomain, 'secure'. I have set up the httpd.conf file so that the documentRoot for secure.foo.com is /home/foo/secure and the documentRoot for www.foo.com is /home/foo/www. The two subdomains also have unique IP addresses.

Here's the applicable section of the httpd.conf file (the IP addresses and paths have been changed to protect the ignorant):

NameVirtualHost 1.2.3.4:80
<VirtualHost 1.2.3.4:80>
DocumentRoot /home/foo/www
ServerName www.foo.com
ServerAlias foo.com
</VirtualHost>
<VirtualHost 5.6.7.8:443>
DocumentRoot /home/foo/secure
ServerName secure.foo.com
SSLEngine On
SSLCertificateFile /path/to/foo.com.crt
SSLCertificateKeyFile /path/to/foo.com.key
</VirtualHost>

The DNS for the domain (foo.com) is set up as follows:

<SOA and other stuff...>
      IN A 1.2.3.4
mail  IN A 2.3.4.5 ;mail on another server
www   IN A 1.2.3.4
secure IN A 5.6.7.8

With this setup, www.foo.com only accepts http traffic and secure.foo.com only accepts SSL (https) traffic.

If I start a PHP session on http://www.foo.com/page.php I can access all of the values I toss into the session from any page on the site. However, as soon as I pull up a page on https://secure.foo.com (and call session_start), the session variables are not there (print_r ($_SESSION) outputs 'array ()').

I have session.cookie_domain in php.ini set to 'foo.com' (I also tried '.foo.com').

It's my understanding that cookies -- including session cookies -- are supposed to be available across subdomains. Does the fact that the subdomains are using different transfer protocols (http v. https) make a difference?

I've looked everywhere for an answer to my problem. Please put me out of my misery and tell me it's something stupid I've overlooked!!!
0
Comment
Question by:dbinteractive
3 Comments
 
LVL 6

Expert Comment

by:peyox
ID: 12129233
0
 
LVL 27

Accepted Solution

by:
Diablo84 earned 500 total points
ID: 12131518
When you are setting cookies in order for them to be available across all subdomains the 5th parameter (domain) must be prefixed with a dot. eg. setcookie("name","value",time()+3600,"/",".foo.com");

The same applies to the session cookie, in your php.ini file you will find a line that reads something like:

; The domain for which the cookie is valid.
session.cookie_domain =

Add your domain prefixed with a . and don't forget to restart your webserver afterwards. eg:

; The domain for which the cookie is valid.
session.cookie_domain = .foo.com
0
 

Author Comment

by:dbinteractive
ID: 12132805
I should have known -- It was something stupid I overlooked.

I didn't realize I had to restart Apache after making changes to php.ini.

For future EE users who may encounter the same problem: in order for cookies (session or otherwise) to be available across subdomains, you must do as Diablo84 (and the PHP manual) says: set the cookie_domain to .foo.com. You can do this either by changing the session.cookie_domain value in your php.ini file or by calling ini_set ("session.cookie_domain", ".foo.com") before you call session_start ().

Funny enough, I had tried both methods yesterday. Neither worked. The php.ini change obviously didn't work because I neglected to restart Apache. Why the second method (ini_set ...) didn't work is beyond me. All I know is I came in this morning and the session data were magically available across my subdomains.

Could be that Apache restarted overnight. Could be that the session ID I was using yesterday kept getting recycled and GC cleaned it up overnight. Either way, it's working now.

Although the problem "fixed itself", I'll give the points to Diablo84 since he reminded me that I have to restart Apache.

Thanks, experts!
0

Featured Post

Free Tool: SSL Checker

Scans your site and returns information about your SSL implementation and certificate. Helpful for debugging and validating your SSL configuration.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
How to pass JavaScript generated HTML text form values to PHP? 5 38
AJAX pass along a variable 3 46
Link failure 16 32
Wordpress Query 5 25
This article will explain how to display the first page of your Microsoft Word documents (e.g. .doc, .docx, etc...) as images in a web page programatically. I have scoured the web on a way to do this unsuccessfully. The goal is to produce something …
I imagine that there are some, like me, who require a way of getting currency exchange rates for implementation in web project from time to time, so I thought I would share a solution that I have developed for this purpose. It turns out that Yaho…
Explain concepts important to validation of email addresses with regular expressions. Applies to most languages/tools that uses regular expressions. Consider email address RFCs: Look at HTML5 form input element (with type=email) regex pattern: T…
The viewer will learn how to dynamically set the form action using jQuery.

856 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question