We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 17403 ☆ A M B ☆
    • 183 Posts
    I using Revo 2.0.8-pl On apache (Linux and Windows)

    Cookies on Revo always return default PHP session name: "PHPSESSID", no matter how I change the value of $site_sessionname on ../core/config/config.inc.php.

    I guess it’s back to function _initSession on ../core/model/modx/modx.class.php.

    <?php
    //line 2843: $site_sessionname always null
    $site_sessionname= $this->getOption('session_name', '');


    I go to system event setting, but there is no "session_name" key (on default installation). So I add that key, and now it’s works.

    Question:
    Regarding to security issue: what the best way to put session_name? on file (config.inc.php) or on database (system event)?

    Cheers
      zaenal.lokamaya
      • 17403 ☆ A M B ☆
      • 183 Posts
      I submit this issue as a bug here http://bugs.modx.com/issues/4073.

      FYI:
      Having session name configurable via system event, will give the ability to change session name, for example, on each context.
        zaenal.lokamaya