-
☆ A M B ☆
- 397 Posts
I am using Revo 2.2.4 with Babel and the client has complained that the session ID is sometimes written in the URL. How can I control this?
Thanks!
Benjamin Davis: American web designer living in Munich, Germany and a MODX Ambassador. I am also co-founder of SEDA.digital, a MODX Agency.
-
☆ A M B ☆
- 24,524 Posts
I believe that if the session cookie is not available, then it will write it in the URL. This is controlled in the PHP configuration.
http://www.php.net/manual/en/session.configuration.php#ini.session.use-only-cookies
-
☆ A M B ☆
- 397 Posts
So I cannot control that from within MODX, right?
Benjamin Davis: American web designer living in Munich, Germany and a MODX Ambassador. I am also co-founder of SEDA.digital, a MODX Agency.
-
☆ A M B ☆
- 24,524 Posts
I'm not sure, you might be able to override it in the .htaccess or in PHP code somewhere. It's supposed to be PHP_INI_ALL. If your PHP is handled via an Apache module, then you can use the .htaccess
php_flag session.use_only_cookies 1
or
php_value session.use_only_cookies 1
In PHP code you'd need something like
ini_set('session.use_only_cookies', 1)
Maybe the Revo dieties can let us know if there is a way to add such directives, perhaps through a custom system setting?