From 5ee0c8d41b73c8ec42dfad173cb093e518c231c4 Mon Sep 17 00:00:00 2001 From: Thanakorn Date: Mon, 14 Sep 2026 12:34:19 +0700 Subject: [PATCH] Keep PHP notices out of login API JSON responses --- app/session.php | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/app/session.php b/app/session.php index 5fb3a0e..3651670 100644 --- a/app/session.php +++ b/app/session.php @@ -2,6 +2,12 @@ // app/session.php ob_start(); // ensure output buffering is on regardless of php.ini — prevents stray output from corrupting JSON API responses +// The buffer is still flushed, so notices would still land in front of the JSON +// body and break the client's parse ("Server error occurred."). The login API +// engines load this file instead of db_auth.php, so apply the same policy here. +ini_set('display_errors', '0'); +ini_set('log_errors', '1'); + if (session_status() === PHP_SESSION_NONE) { // Derive cookie path dynamically from the current script location.