Naming consistance and SESSION issue

This commit is contained in:
Thanakorn S
2026-05-08 12:04:10 +07:00
parent e4a35c7fac
commit 304848d3f4
18 changed files with 69 additions and 41 deletions
+15 -3
View File
@@ -1,13 +1,25 @@
<?php
// app/session.php
if (session_status() === PHP_SESSION_NONE) {
// Reject client-supplied session IDs — prevents session fixation.
// Derive cookie path dynamically from the current script location.
// e.g. /tr3wms/app/login/api/engine/login_otp.php → /tr3wms/
// This relies on the app always living one level under the repo root:
// DOCUMENT_ROOT/
// tr3wms/ ← repo root (cookie path)
// app/
// session.php ← this file is always inside app/
$parts = explode('/', trim($_SERVER['SCRIPT_NAME'], '/'));
$repo_name = '/' . $parts[0] . '/'; // e.g. /tr3wms/
ini_set('session.use_strict_mode', 1);
// Server-side session file lifetime: 1 hour.
ini_set('session.gc_maxlifetime', 3600);
ini_set('session.cookie_path', $repo_name);
ini_set('session.cookie_httponly', 1);
ini_set('session.cookie_samesite', 'Lax');
session_set_cookie_params([
'lifetime' => 0,
'path' => '/wms/',
'path' => $repo_name,
'domain' => '',
'secure' => isset($_SERVER['HTTPS']) && $_SERVER['HTTPS'] === 'on',
'httponly' => true,