37 lines
1.5 KiB
PHP
37 lines
1.5 KiB
PHP
<?php
|
|
// app/session.php
|
|
ob_start(); // ensure output buffering is on regardless of php.ini — prevents stray output from corrupting JSON API responses
|
|
|
|
// The buffer is still flushed, so notices would still land in front of the JSON
|
|
// body and break the client's parse ("Server error occurred."). The login API
|
|
// engines load this file instead of db_auth.php, so apply the same policy here.
|
|
ini_set('display_errors', '0');
|
|
ini_set('log_errors', '1');
|
|
|
|
if (session_status() === PHP_SESSION_NONE) {
|
|
|
|
// Derive cookie path dynamically from the current script location.
|
|
// e.g. /wms/app/login/api/engine/login_otp.php → /wms/
|
|
// This relies on the app always living one level under the repo root:
|
|
// DOCUMENT_ROOT/
|
|
// wms/ ← repo root (cookie path)
|
|
// app/
|
|
// session.php ← this file is always inside app/
|
|
$parts = explode('/', trim($_SERVER['SCRIPT_NAME'], '/'));
|
|
$repo_name = '/' . $parts[0] . '/'; // e.g. /wms/
|
|
|
|
ini_set('session.use_strict_mode', 1);
|
|
ini_set('session.gc_maxlifetime', 3600);
|
|
ini_set('session.cookie_path', $repo_name);
|
|
ini_set('session.cookie_httponly', 1);
|
|
ini_set('session.cookie_samesite', 'Lax');
|
|
session_set_cookie_params([
|
|
'lifetime' => 0,
|
|
'path' => $repo_name,
|
|
'domain' => '',
|
|
'secure' => isset($_SERVER['HTTPS']) && $_SERVER['HTTPS'] === 'on',
|
|
'httponly' => true,
|
|
'samesite' => 'Lax',
|
|
]);
|
|
session_start();
|
|
} |