Skip to main content ↑ ↓
PhpSessionId & Cookies Started by Hj Ahmad Rasyid Hj Ismail · · Read 47 times 0 Members and 1 Guest are viewing this topic.

PhpSessionId & Cookies

I am not sure whether I should talk about this in close thread or an open one, but I decided the later might be best. I guess phpsessionid and cookies should by default use the forum set domain, not its top level domain, but since 1.0 (even smf), it has been using top level domain. I am not sure how this forum which should have the same built manage to set it correctly to www.elkarte.net. In mine, phpsessionid always remain the tld .sch.my, while for cookies, I only manage to set it to the forum domain using subdomain cookies settings, and add into the column below it the forum domain, elkarte.sch.my for 1.1 and elkarte2.sch.my for 2.0. I think it shouldn't be like that, and the default must always use the fully qualified domain name set for the forum, as well as its path/dir, if using any. Is the file for session used in this forum different causing phpsessionid to be correctly using FQDN set for the forum?

Re: PhpSessionId & Cookies

Reply #1 –

What about sites that use like a CMS that also logs cookies, as top then the forum as sub?
ElkArte here has everything logged into the same, but some sites have 2 different, one for main site and one for the forum.
I think it should be where it's easily set to how the admin wants it, whether the main domain, or subdomain.
If using just a directory, instead of sub-domain, then make it cover the whole domain, perhaps?

Re: PhpSessionId & Cookies

Reply #2 –

I going to start by writing down what the system should be doing and lets go from there, meaning is it not doing this or it is doing this buts its wrong.

  • Neither Local nor Global is checked: Standard single domain or single subdomain forums (forum.example.com or example.com).  This generally should maximize compatibility while preventing subdomain cross talk / cookie leakage.  This is how this site is setup.

  • Enable Local Cookies (localCookies) checked: Multiple distinct forum/app installations sharing the exact same hostname and path (e.g., example.com/forum1 vs example.com/forum2).  Scopes cookies strictly to the subfolder, and disables login persistence in parent directories.

  • Enable Global Cookies (globalCookies) checked: A single login required across different subdomains (e.g., sharing login between forum.example.com and www.example.com). Allows subdomain session sharing, but requires proper domain scope entry in the "Main domain used for subdomain" (globalCookiesDomain) to avoid conflicts.  I will note that if not filled in, ElkArte will set a default one (like .example.com) however it will fail to this correctly if the domain contains a ccTLD  such as .sch.my, .co.uk, or .com.au

Re: PhpSessionId & Cookies

Reply #3 –

So basically I should not have chosen subdomain cookies there, and there is no necessities to fix forum domain there after. That seems to work great except the fact that phpsessionid is correct when that parts are left out, but when checked and filled, it becomes tld again, which it should not right? As the right one would be phpsessionid must always is the fqdn set for the forum, right?