【问题标题】:Redirecting cookieless sessions in PHP without clicking a link在 PHP 中重定向无 cookie 会话而不单击链接
【发布时间】:2011-07-06 00:26:57
【问题描述】:

我一直在与无 cookie 会话解决方案战斗。当然,无 cookie 会话解决方案非常棒。我在实现它时遇到了麻烦,因为我在重定向到另一个页面后无法读取会话信息。

这是我在 testcode.php

中的测试代码
<?php
ini_set('session.use_trans_sid', '1');

session_start();

if (isset($_GET['pagecode'])) {
    session_id($_GET['pagecode']);
print_r($_SESSION); // **cannot read session information here**
exit();
}

if (isset($_SESSION['cookieconfirmed']) && $_SESSION['cookieconfirmed'] == 1) {

} else {
/** Checks if the user's browser is cookie-enabled **/
    if (isset($_GET['redirected'])) {  // if the page has gotten redirected
        $_SESSION['cookieconfirmed'] = 1;  // confirmed the cookie-disability
        if (isset($_COOKIE['testcookie'])) {
            header ('location: testcode.php');
        } else {
           header('location: testcode.php?pagecode=' . session_id());
        }
    } else {
       setcookie('testcookie', 'OK');  //sets a test cookie.
       header('location: testcode.php?redirected=1'); // redirects the page to check     cookie-disability
    }

    exit(0);
}
?>

如您所见,此代码不起作用。但是,如果我通过单击链接重定向到另一个页面,效果很好。这是 testcode.php 中的代码:

<?php
ini_set('session.use_trans_sid', '1');

session_start();

if (isset($_GET['pagecode'])) {
    session_id($_GET['pagecode']);
print_r($_SESSION); // **able to read session information here**
exit();
}

if (isset($_SESSION['cookieconfirmed']) && $_SESSION['cookieconfirmed'] == 1) {

} else {
/** Checks if the user's browser is cookie-enabled **/
    if (isset($_GET['redirected'])) {  // if the page has gotten redirected
        $_SESSION['cookieconfirmed'] = 1;  // confirmed the cookie-disability
        if (isset($_COOKIE['testcookie'])) {
            header ('location: testcode.php');
        } else {
           echo '<a href="testcode.php?pagecode=' . session_id() . '">Click here to continue</a>';
        }
    } else {
       setcookie('testcookie', 'OK');  //sets a test cookie.
       header('location: testcode.php?redirected=1'); // redirects the page to check     cookie-disability
    }

    exit(0);
}
?>

如何在不点击链接的情况下使其工作?

【问题讨论】:

  • 由于没有格式化,因此很难理解您的代码...如果您在每行代码之前放置(至少)四个空格,则它应该显示为格式化
  • 你真的应该重新考虑使用无cookie会话。除非你非常小心,否则你最终会得到session fixation vulnerabilities。最佳实践不仅建议基于 cookie 的会话,还建议强制“仅 cookie”模式。
  • @Charles:我会将除非您非常小心更改为无,因为使用 URL 会话标识符会导致会话固定和会话泄露漏洞。

标签: php session redirect header cookieless


【解决方案1】:
ini_set('session.use_trans_sid', '1');

你必须在你的每一个 PHP 页面上都有这个 - 你不能只在会话处理脚本中这样做。如果 PHP 生成页面时它没有打开,它不会将会话 ID 插入到该页面上的表单和 URL 中。因此,最好将其放入您的 php.ini 或至少 httpd.conf/.htaccess(作为 php_value)使其成为所有脚本的全局选项。

【讨论】:

  • 感谢您的宝贵回答。
【解决方案2】:
PHP function for this is :


function append_sid($link) {
    if(session_id() !== NULL && !isset($_COOKIE['PHPSESSID'])) {
        if(strpos($link, "?") === FALSE) {
            return $link . "?PHPSESSID=" . session_id();
        } else {
            return $link . "&PHPSESSID=" . session_id();
        }
    } else {
        return $link;
    }
}


Javascript Function for this is:


function append_sid(link) {
    <?php if(session_id() !== NULL && !isset($_COOKIE['PHPSESSID'])) { ?>
        var session_id = '<?php echo session_id ?>';
        if(link.indexOf('?') == -1) {
            return link + '?PHPSESSID=' + session_id;
        } else {
            return link + '&PHPSESSID=' + session_id;
     }
    <?php } else { ?>
        return link;
    <?php } ?>
}


A caveat – passing session id by URL requires the session.session.use_trans_sid tio be set to 1. 

php_value session.use_trans_sid = 1 in the .htaccess file. You can also try the function:

ini_set('session.use_trans_sid', '1')

【讨论】:

    猜你喜欢
    • 2013-07-08
    • 1970-01-01
    • 1970-01-01
    • 1970-01-01
    • 1970-01-01
    • 1970-01-01
    • 2016-08-27
    • 1970-01-01
    • 1970-01-01
    相关资源
    最近更新 更多