Showing posts with label session. Show all posts
Showing posts with label session. Show all posts

Friday, October 9, 2009

Session problem in IE when using iframes

Problem:
I have a site made with php which uses server side sessions. I used iframes to embed the pages in other website . When using internet explorer with the default privacy setting, Medium, I am not able to create a session due to the fact that a cookie will not be accepted by Internet Explorer.

The situation is that when the frame has been created by one server, and the child frame then loads content from a second server, Internet Explorer treats all cookies from the second server (in the child frame) as 3rd party cookies. Under the Medium privacy level, cookies are not allowed from the secondary server because Internet Explorer Blocks third-party cookies that do not have a compact privacy policy. To fix this problem, a compact privacy policy must be added to the headers sent to the client before a cookie is attempted to be created

Solution:
The problem occurred due to the absence of a valid privacy policy (P3P). to include that we can add a header to the child pages inside iframes

eg: header('P3P:CP="IDC DSP COR ADM DEVi TAIi PSA PSD IVAi IVDi CONi HIS OUR IND CNT"');

This will vary according to the privacy policy
some useful references below

P3P details

p3p policy editor from IBM

http://www.alphaworks.ibm.com/tech/p3peditor


references



Tuesday, September 29, 2009

Symfony 1.2 User sessions and sfGuard

Symfony automatically manages user sessions and is able to keep persistent data between requests for users. It uses the built-in PHP session-handling mechanisms and enhances them to make them more configurable and easier to use.

Symfony's session-handling feature completely masks the client and server storage of the session IDs to the developer. However, if you want to modify the default behaviors of the session-management mechanisms, it is still possible. This is mostly for advanced users.

On the client side, sessions are handled by cookies. The symfony session cookie is called symfony, but you can change its name by editing the factories.yml configuration file, as shown


all:   
  storage:     
    class: sfSessionStorage    
    param:       
      session_name: my_cookie_name

in factories.yml


On the server side, symfony stores user sessions in files by default.

Session expiration occurs automatically after 30 minutes. This default setting can be modified for each environment in the same factories.yml configuration file, but this time in the user factory, as shown

all:   
  user:    
    class:       myUser     
    param:       
      timeout:   1800   # Session life in sec