Quote from: rossco at May 14, 2009, 08:59 AM
Both apps are on the same server but using separate databases. I don’t know much about cookies so I am unsure on how to do this.
Unfortunately, this is where you typically have some choices, and none of them are that good. The problem is that each PHP application uses sessions in a unique way; there is in a sense, too much flexibility built in to PHP sessions and no standards with which applications are constructed upon this session framework. In addition to making sure the session cookies are configured the same for both apps, you’ll need to know precisely what each application expects in it’s session, how it manages the session_id’s, and pretty much every other detail of the application that depends on session data. For a forum app, that is just about everything in it, as it is for a CMS framework like MODx. I think you see the conflict of interest.
For example, in order to provide extra security against session fixation attacks, most PHP applications periodically rewrite the session id whenever certain events occur, for instance, a user logs in and performs an action which adds them to a new security group with new permissions; the app will typically clear all the session data and reload it at that point. So in order to integrate and use the same sessions on two applications designed by different people, you have to accommodate all of the needs of both apps at every point where the apps depend on session data. This is no small task in many cases, and the best you can hope for is real-time sync’ing of user data so that each application has everything it needs to manage its own sessions using the same set of users.