DML73:
... "Force Cookie Use" does? (Admin -> Configuration -> Sessions - Force Cookie Use).
What exactly are the advantages and disadvantages? ...
Basically it controls how the session id (identifies the end user's login, shopping cart, etc) is sent from the visitors web browser to the server.
In Zen Cart 1.5.0 - 1.5.3:
zenid = session id
Enabled
- If no session id (cookie), server creates new session
- If session id (cookie) load session using the session id
- If no cookie, server requests the visitors browser set a cookie containing the session id
- Content is sent to the website visitor
Enabling the feature will break things for those with cookies disabled (or filtered)... But ensures visitors never see the session id in the URL (or copy / paste the URL w/ session id)... They could still grab the session id from the cookie (as could any proxies).
Disabled
- If no session id (cookie or URL), server creates new session
- If session id (cookie or URL) load session using the session id
- If no cookie, server requests the visitors browser set a cookie containing the session id
- If no cookie, server adds the session id to the URL
- Content is sent to the website visitor
This allows visitors with cookies disabled (or anti-virus / anti-malware programs blocking / cleaning the cookies) to function. But it also lets the visitor potentially see a URL with the zenid and copy / paste / share the URL with friends (and thus share the session as well until the session expires).
Since at least Zen Cart 1.3.9h, a canonical link is generated for each page and will never contain the zenid (search engines use the canonical link as a strong hint of the correct URL to display in Search Results). The canonical link should also be used with OpenGraph tags (to control the URL shown in social media when someone copy / pastes).
Additionally, one can request search engines not index URLs containing ?zenid= (I currently do this) in the robots.txt.