We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 28000 ☆ A M B ☆
    • 397 Posts
    I am using Revo 2.2.4 with Babel and the client has complained that the session ID is sometimes written in the URL. How can I control this?

    Thanks!
      Benjamin Davis: American web designer living in Munich, Germany and a MODX Ambassador. I am also co-founder of SEDA.digital, a MODX Agency.
      • 28042 ☆ A M B ☆
      • 24,524 Posts
      I believe that if the session cookie is not available, then it will write it in the URL. This is controlled in the PHP configuration.

      http://www.php.net/manual/en/session.configuration.php#ini.session.use-only-cookies
        Studying MODX in the desert - http://sottwell.com
        Tips and Tricks from the MODX Forums and Slack Channels - http://modxcookbook.com
        Join the Slack Community - http://modx.org
        • 28000 ☆ A M B ☆
        • 397 Posts
        So I cannot control that from within MODX, right?
          Benjamin Davis: American web designer living in Munich, Germany and a MODX Ambassador. I am also co-founder of SEDA.digital, a MODX Agency.
          • 28042 ☆ A M B ☆
          • 24,524 Posts
          I'm not sure, you might be able to override it in the .htaccess or in PHP code somewhere. It's supposed to be PHP_INI_ALL. If your PHP is handled via an Apache module, then you can use the .htaccess

          php_flag session.use_only_cookies  1

          or
          php_value session.use_only_cookies 1


          In PHP code you'd need something like
          ini_set('session.use_only_cookies', 1)


          Maybe the Revo dieties can let us know if there is a way to add such directives, perhaps through a custom system setting?
            Studying MODX in the desert - http://sottwell.com
            Tips and Tricks from the MODX Forums and Slack Channels - http://modxcookbook.com
            Join the Slack Community - http://modx.org