Page 4 of 4

Posted: Mon 14. Feb 2005, 22:33
by liquiqvisions
[session]
; Handler used to store/retrieve data.
session.save_handler = files

; Argument passed to save_handler. In the case of files, this is the path
; where data files are stored. Note: Windows users have to change this
; variable in order to use PHP's session functions.
session.save_path = "3;/www/php"

; Whether to use cookies.
session.use_cookies = 1

; This option enables administrators to make their users invulnerable to
; attacks which involve passing session ids in URLs; defaults to 0.
; session.use_only_cookies = 1

; Name of the session (used as cookie name).
session.name = PHPSESSID

; Initialize session on request startup.
session.auto_start = 0

; Lifetime in seconds of cookie or, if 0, until browser is restarted.
session.cookie_lifetime = 0

; The path for which the cookie is valid.
session.cookie_path = /

; The domain for which the cookie is valid.
session.cookie_domain =

; Handler used to serialize data. php is the standard serializer of PHP.
session.serialize_handler = php

; Define the probability that the 'garbage collection' process is started
; on every session initialization.
; The probability is calculated by using gc_probability/gc_divisor,
; e.g. 1/100 means there is a 1% chance that the GC process starts
; on each request.

session.gc_probability = 1
session.gc_divisor = 1000

; After this number of seconds, stored data will be seen as 'garbage' and
; cleaned up by the garbage collection process.
session.gc_maxlifetime = 1440

; PHP 4.2 and less have an undocumented feature/bug that allows you to
; to initialize a session variable in the global scope, albeit register_globals
; is disabled. PHP 4.3 and later will warn you, if this feature is used.
; You can disable the feature and the warning seperately. At this time,
; the warning is only displayed, if bug_compat_42 is enabled.

session.bug_compat_42 = 0
session.bug_compat_warn = 1

; Check HTTP Referer to invalidate externally stored URLs containing ids.
; HTTP_REFERER has to contain this substring for the session to be
; considered as valid.
session.referer_check =

; How many bytes to read from the file.
session.entropy_length = 0

; Specified here to create the session id.
session.entropy_file =

;session.entropy_length = 16

;session.entropy_file = /dev/urandom

; Set to {nocache,private,public,} to determine HTTP caching aspects.
; or leave this empty to avoid sending anti-caching headers.
session.cache_limiter = nocache

; Document expires after n minutes.
session.cache_expire = 180

; trans sid support is disabled by default.
; Use of trans sid may risk your users security.
; Use this option with caution.
; - User may send URL contains active session ID
; to other person via. email/irc/etc.
; - URL that contains active session ID may be stored
; in publically accessible computer.
; - User may access your site with the same session ID
; always using URL stored in browser's history or bookmarks.
session.use_trans_sid = 0

; The URL rewriter will look for URLs in a defined set of HTML tags.
; form/fieldset are special; if you include them here, the rewriter will
; add a hidden <input> field with the info which is otherwise appended
; to URLs. If you want XHTML conformity, remove the form entry.
; Note that all valid entries require a "=", even if no value follows.
url_rewriter.tags = "a=href,area=href,frame=src,input=src,form=fakeentry"
May I add that I had previously installed 1.4 and it worked with no problem..

Posted: Tue 15. Feb 2005, 00:34
by Oliver Georgi
then try to use checklogin form that older release.

Oliver

Posted: Tue 15. Feb 2005, 06:32
by liquiqvisions
:( Tried it, Still the same result.

Also this problem is much worst on Internet Explorer. Sometimes it won't even let me login.

I usualy use Firefox and can login, but with the said problems..


I was wondering if I could use "checklogin.php" from 1.4 ?

Posted: Wed 16. Feb 2005, 23:06
by liquiqvisions
I am using "checklogin" from the 1.4 release, and so far it seems to be working fine. Are/would there be any problems with this ??

Posted: Wed 16. Feb 2005, 23:38
by Oliver Georgi
no - it's OK.

Oliver

Posted: Mon 18. Apr 2005, 21:50
by cyppher.nl
I cannot login in phpwcms backend in Internet Explorer to.
I've tried the checklogin.php file (the most recent one), there actually IS a login, (users logged in: admin) but the login.php file is what I see...

In Firefox there's no problem logging in and the backend pages are shown correctly.

Oliver, or anyone else, what to do??

Might it be somy hidden settings in IE?

Posted: Mon 18. Apr 2005, 21:55
by Pappnase
cyppher.nl wrote:I cannot login in phpwcms backend in Internet Explorer to.
I've tried to copy (and configure) the login.php file from 1.1RC4 install, there actually IS a login, (users logged in: admin) but the login.php file.

In Firefox there's no problem logging in and the backend pages are shown correctly.

Oliver, what to do?
Might it be somy hidden settings in IE?
hello

no double psotings please!

http://www.phpwcms.de/forum/viewtopic.php?t=6637

Posted: Mon 18. Apr 2005, 21:58
by cyppher.nl
it is actually no double post, as I've put my feedback on Oliver's solution (checklogin.php) in that post.
sorry if that seems like a double post (not my intentions, I moderate several forums so I know the annoying crossposters).

Posted: Mon 18. Apr 2005, 22:00
by Pappnase
cyppher.nl wrote:it is actually no double post, as I've put my feedback on Oliver's solution (checklogin.php) in that post.
sorry if that seems like a double post (not my intentions, I moderate several forums so I know the annoying crossposters).
hello

wich php release did you use!?

Posted: Mon 18. Apr 2005, 22:04
by cyppher.nl
Pappnase wrote:wich php release did you use!?
this is extracted from phpinfo() :

Code: Select all

PHP Version 4.3.6

System 	Windows NT CYPPHER 5.1 build 2600
Build Date 	Apr 14 2004 17:17:11
Server API 	Apache
Virtual Directory Support 	enabled
Configuration File (php.ini) Path 	D:\WINDOWS\php.ini
PHP API 	20020918
PHP Extension 	20020429
Zend Extension 	20021010
Debug Build 	no
Thread Safety 	enabled
Registered PHP Streams 	php, http, ftp, compress.zlib

Posted: Mon 18. Apr 2005, 22:05
by Oliver Georgi
Maybe cookies support missing in IE.

Oliver

Posted: Mon 18. Apr 2005, 22:07
by cyppher.nl
Oliver Georgi wrote:Maybe cookies support missing in IE.
I can't imagine that is true, because other sites use cookies too, and without any problems I can see those sites.
(in my Temp.Internet Files directory there's cookies from this forum and from google, I deleted cookies one hour ago)

but how to solve my login problems in IE?

Posted: Mon 18. Apr 2005, 22:22
by cyppher.nl
In FireFox everything is working fine now, I've configured IE so that it must accept every cookie and script in the local internet zone. However, still no backend login possible...

Posted: Mon 18. Apr 2005, 23:02
by Oliver Georgi
Hm, I really don't know.

Oliver

Please check fireall settings

Posted: Tue 19. Apr 2005, 01:34
by rsantifort
I had to edit the zonelabs zonealarm security suite cookie settings.
Removed all tje checkmarks with 3th party cookies!