Zen Cart Logo
Forums / General Questions / Database storage of session

Database storage of session

Locked

Views: 2,704

Results 1 to 9 of 9
This thread is locked. New replies are disabled.
1 Jan 2007, 5:12 PM
#1
athena avatar

athena

Totally Zenned

Join Date:
Jan 2006
Location:
NM
Posts:
740
Plugin Contributions:
0

Database storage of session

In an older thread Dr Byte said:

The webserver handles SSL and NONSSL activities as separate activities from separate sites. This runs the risk of having your session data not available if the filesystem references aren't available from the "other" site.
Granted, if all the files are handled from the same place, the risk is limited.
However, if it's all stored in the database, it's all available regardless of which server it's coming from.
Further, having any security information left in O/S files is a sensitive issue to many.
Also, files are vulnerable to changes made server administrators related to permissions. If 777 rights were ever prevented by the admin, your site would be down until the sessions files could be written again.

Both options work, but I recommend database for almost all cases.

  1. Can I do this through the control panel? Configuration>Sessions ?

  2. This is prompted by a customer wanting secure login. Currently I'm using the default settings for what is and isn't secure. Can someone tell me where the default ssl settings are as we notice since our 1.3.2 upgrades that some admin pages are secure and some are not as well.

1 Jan 2007, 8:10 PM
#2
athena avatar

athena

Totally Zenned

Join Date:
Jan 2006
Location:
NM
Posts:
740
Plugin Contributions:
0

Re: Database storage of session

Some further info on my dilemma:

  1. In includes/configure.php in my up to date version of 1.3.2 Line 55 it says

define('STORE_SESSIONS', ''); // leave empty '' for default handler or set to 'db'

Is this all I have to do is put db in the '' as displayed here: 'db' then up load the file? Then what do I set it to in the Admin>configuration>sessions? Erase the path to my current file and leave blank? Should I risk this at all? This is the first time a customer has asked about secure login pages but it may be a problem we didn't know to look for.

  1. OK, I remember defining my https in includes/configure.php but is the application of https or secure pages dictated by some code on that page? If not, where and how? Because in my up to date version of 1.3.2 not all pages are secure in the admin or the login procedure.
1 Jan 2007, 8:22 PM
#3
Kim avatar

Kim

Obaa-san

Join Date:
Jun 2003
Location:
West Coast, North America
Posts:
26,627
Plugin Contributions:
0

Re: Database storage of session

Zen Cart is smart and switches in and out of SSL mode based on the page.

1 Jan 2007, 8:30 PM
#4
athena avatar

athena

Totally Zenned

Join Date:
Jan 2006
Location:
NM
Posts:
740
Plugin Contributions:
0

Re: Database storage of session

Hi Kim...So it is, but can I make the log-in pages secure?

By the way, Happy New Year and "thanks" to all you zen folks via paypal for making a programmer out of me!

1 Jan 2007, 8:36 PM
#5
Kim avatar

Kim

Obaa-san

Join Date:
Jun 2003
Location:
West Coast, North America
Posts:
26,627
Plugin Contributions:
0

Re: Database storage of session

The login pages and checkout should be secure if it is configured properly. Please post your includes/configure.php without your password.

1 Jan 2007, 8:38 PM
#6
athena avatar

athena

Totally Zenned

Join Date:
Jan 2006
Location:
NM
Posts:
740
Plugin Contributions:
0

Re: Database storage of session

Sorry for the misleading info on that subject...I must have inadvertantly fixed the problem the customer was having as the login is now showing as secure throughout the process...but I am still interested in the necessity of changing from a file to the db for my sessions as we have had some customers with problems from time to time and DrByte's info seems to address this or at least be a good thing to try. Just need to know how to do it...if uploading the configure.php is all I have to do?

2 Jan 2007, 9:55 PM
#7
athena avatar

athena

Totally Zenned

Join Date:
Jan 2006
Location:
NM
Posts:
740
Plugin Contributions:
0

Re: Database storage of session

So I'm down to this question: In order to avoid problems with sessions and follow through on the above quote fy Dr Byte:

In includes/configure.php in my up to date version of 1.3.2 Line 55 it says

define('STORE_SESSIONS', ''); // leave empty '' for default handler or set to 'db'

Is this all I have to do is put db in the '' as displayed here: 'db' then up load the file? Then what do I set it to in the Admin>configuration>sessions? Erase the path to my current file and leave blank? Should I risk this at all?

3 Jan 2007, 12:03 AM
#8
drbyte avatar

drbyte

Sensei

Join Date:
Jan 2004
Posts:
63,513
Plugin Contributions:
176

Re: Database storage of session

If you wish you may change STORE_SESSIONS from '' to 'db' and just upload the file.
You should do the same for both configure.php files

In Admin->Configuration->Sessions, just leave things alone. Do NOT blank out the path.

3 Jan 2007, 1:35 AM
#9
athena avatar

athena

Totally Zenned

Join Date:
Jan 2006
Location:
NM
Posts:
740
Plugin Contributions:
0

Re: Database storage of session

Thank you, DrByte.