We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 5329
    • 2 Posts

    I have searched the forums but haven’t found an answer so will ask here. I have a web site up using modx with smf for the forums. I am having a difficult time keeping the users logged in even if they click "remember me". If the php session information has been garbage collected, then the modx pages require a login again, but the smf pages do not. The smf login is working fine as it saves the session info in the database. The problem is when users switch between the pages, they are still logged in to the smf forums, but not the modx pages. It causes quite a bit of confusion when they are logged in on one page, but not the other.

    I have configured php to use a directory (session.save_path) for the sessions, yet something is still garbage collecting them every day or so. This is on a fedora core 5 (linux) system, apache, php 5.1.6. Even if I figure out what is garbage collecting the sessions, I still need a way for the users to be remembered forever if they want so they do not have to log in again. I don’t think depending on the session being there is going to work if they do not access the system for a week or so.

    I notice that on this site, I can login and say "forever". Is this the smf login?

    Any pointers to discussions about this or other help would be appreciated.
      • 22303 MODX Staff
      • 10,725 Posts
      Which version of MODx? Until the 0.9.5 final release, there was a major problem with the cookies being used for MODx login. They were basically useless and would not re-initiate an existing session once the browser was closed. This is fixed in 0.9.5, but I’m not sure the SMF bridge has been thoroughly tested with this release.

      Regardless though, the fact remains that SMF uses a db and can persist the session beyond the PHP garbage collection time out, which is generally set to happen every 20 minutes by default. MODx does not, and is limited by the php.ini settings. You can attempt to set these in the startCMSSession() function defined in the config.inc.php file, and I believe there are some posts in this regard here in the forums that might help out; I just can’t find them at the moment...

      The next minor release of MODx (0.9.7) will include db session management by default, and will also allow custom session management implementations to make these kinds of integrations much easier to deal with.
        • 5329
        • 2 Posts
        Thanks for your response!

        My site is currently running on Modx 0.9.2.1 but I have upgraded to 0.9.5 and am testing it a bit before upgrading the site itself. I did a quick test and it seemed that the cookie/session interaction was the same but I am happy to hear that the cookie interaction is improved with this release. I will install it soon and hopefully my users will not have to log in everytime.

        I did find the discussion on setting the garbage collection timeout, but my users want to login once and never again (for a year or so) so the best solution is to have the session info in the database.

        It is great to hear that 0.9.7 will have database session integration. I will look forward to that and would like to test it whenever it is available. If I get the svn version (for testing only) would that integration be in now?

        Thanks again, and thanks to everyone involved for creating this great framework.

        This is my site if anyone is interested: http://www.photocritiq.com

        Cindy

          • 22303 MODX Staff
          • 10,725 Posts
          Quote from: CindyM at Dec 18, 2006, 04:22 PM

          I did find the discussion on setting the garbage collection timeout, but my users want to login once and never again (for a year or so) so the best solution is to have the session info in the database.

          It is great to hear that 0.9.7 will have database session integration. I will look forward to that and would like to test it whenever it is available. If I get the svn version (for testing only) would that integration be in now?
          Yep, unfortunately, the only way you’re going to be able to keep the MODx session alive that long is wait for the db session support.

          The current SVN trunk is still hosting 0.9.5, but I will be merging the 0.9.7 branch to trunk, hopefully before the end of the month, to coincide with an early alpha release of 0.9.7. We’ll likely have a patch release (0.9.5.1) before that happens, which will include any recent bug fixes to the current release, all the latest snippets, and all the additional translations we can squeeze in.