We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 15001
    • 697 Posts
    Hello,

    I need some advice...
    For a webservice, I have to change the interface dynamically depending on user choices.
    As Javascript is the perfect language for this, I also use it to store instantly in cookies the changes that occurs.

    This sounds logical to me, but I want to be sure that I did the right choice and that I should not use PHP session cookie variables instead.

    I want all user preferences to be stored 3 days or even more. (The risk of erasing cookies is not important in this case.)

    The cookies that I write in Javascript are without time limit.
    I read somewhere that such cookies are destroyed when the session ends. So, this would suit my needs.
    I’m however not sure if the word "session" here relates to a PHP session or something else, and what happens if no PHP session is created.

    Currently, I set PHP session duration with
    ini_set('session.gc_maxlifetime', '259200'); // 3 days


    Then, I create or get existing session in PHP with session_start().
    Lastly, I check if cookies are enabled (SID must be null).

    Concerning PHP session cookies, I am wondering if all the session variables are stored in a unique session cookie (and PHP parse it to extract the variables) or if PHP creates as many cookies as there are session variables to store.
    I ask this because of the 20 cookies/domain limit.

    I hope that I can keep my Javascript based approach.
    Currently my cookies store composite information (because of the 20 cookies limit) and I parse the cookies content to get key-value pairs.

    Are there major drawbacks in setting cookies with Javascript ?

    Thanks sharing your experience.

    Javascript based approach (with custom functions) :
    WriteACookie('someKeyValuePairs', value);
    
    // Read cookie value that will be parsed afterwards
    var cookieContent = ReadACookie('someKeyValuePairs');

    PHP based approach:
    <?php 
    
    $_SESSION['variable'] = $valeur ;
    
    if(isset($_SESSION['variable'])) 
      valeur = $_SESSION['variable'];
    ?>
      • 28042 ☆ A M B ☆
      • 24,524 Posts
      The SESSION is only good for the current session; additionally it can time out if the user is inactive for more than a few minutes at a time. You can use PHP (snippets or plugins) to set custom cookies, or Javascript. I don’t see much difference between the two, although I tend to avoid Javascript solutions unless I’m doing some fancy AJAX stuff.

      http://php.net/manual/en/function.setcookie.php
      http://www.satya-weblog.com/2007/05/php-and-javascript-cookie.html
        Studying MODX in the desert - http://sottwell.com
        Tips and Tricks from the MODX Forums and Slack Channels - http://modxcookbook.com
        Join the Slack Community - http://modx.org
        • 15001
        • 697 Posts
        Hi Susan,

        Thanks for your answer and the 2 useful links.
        I must still read the 2nd one more carefully.

        Standard cookies are also removed when the browser closes, unless some expiration time is specified. ("expire" argument let null when writing cookie)

        So, I cannot see major difference in using cookies rather than session variables, excepted how information can be accessed. Cookies seem nicer than sessions variables when working with frames (and iframes of course).

        A priori, synchronizing cookies with sessions must be quite easy.

        Bye.
          • 9130
          • 171 Posts
          Let me try and clear things up, there are three types of temporary storage here:
          - Session variables are stores in server memory and are deleted when the php session ends, normally after about 20 minutes of no user activity.
          - Cookies without an expire date are stored in the users browser and are deleted when the browser session ends (i.e. the browser is closed).
          - Cookies with an expire date are stored in the browser until they expire although the user can choose to remove them sooner.

          Other then this there are other differences, mainly concerning security and performance. The most important thing to remember is that cookies can be read and modified by the user so don’t trust them too much. There is no difference between cookies stored through js and ones stored through php, they are the same.
            • 15001
            • 697 Posts
            Thanks.

            There is no difference between cookies stored through js and ones stored through php, they are the same.

            True that they’re the same, but cookies sent though PHP have there values stored on server side in $_COOKIES[’cookiename’]. Therefore, their values can be easily accessed again from the PHP script. However, this is only true from the script that sent the cookies.

            Another difference is that in PHP, cookies must be set before any HTML content (since they are set from the HTTP header). By writing Javascript code from PHP it is possible to set the cookies later, in the document content.