CRE Loaded Community

Banner


Board index » Web Design and Development » Development Discussions

All times are UTC - 5 hours




Post new topic Reply to topic  [ 4 posts ] 
Author Message
 Post subject: Broken who's online and session information
PostPosted: Wed Sep 28, 2011 8:52 am 
Offline
CRE Newbie

Joined: Wed Jul 15, 2009 8:12 pm
Posts: 16
Hi, all

CreLoaded 6.4.1a B2B
I found that who's online not working properly. It does not show if customers have shopping cart.
OK, started digging in and found that whos_online module looks in the session information for cart content. Customer session information is extracted from database. However session information does not make sense. Looks like it is an encoded blob.
At the same time, same code runs perfectly OK on a different server. And session information is plain text.

So, now I am stuck. I have no idea if there is a PHP setting that will cause session information to be encrypted. Given it is same code that runs on tw different servers, I assume problem is somewhere in PHP settings.

Anyway, any ideas are greatly appreciated.

Thanks
Rudolf


Top
 Profile  
 
 Post subject: Re: Broken who's online and session information
PostPosted: Wed Sep 28, 2011 12:49 pm 
Offline
CRE Legend
User avatar

Joined: Thu Jun 12, 2008 6:39 am
Posts: 2394
Location: New Zealand
Probably got suhosin (hardened php) running on the server where the session data is being written encrypted to the sessions table.

suhosin.session.encrypt = on

Hosting company choice - doubt they'd switch it off. So unless you're on your own box ... that's security for yer.

Simon

_________________
www.codemehappy.com
For Cre Loaded tips, how-to articles and more


Top
 Profile  
 
 Post subject: Re: Broken who's online and session information
PostPosted: Wed Sep 28, 2011 4:53 pm 
Offline
CRE Newbie

Joined: Wed Jul 15, 2009 8:12 pm
Posts: 16
Thanks,

I think you are right -- suhosinis plugin is in use. How does one decode session information when it is encrypted?

Thanks,
Rudolf


Top
 Profile  
 
 Post subject: Re: Broken who's online and session information
PostPosted: Thu Sep 29, 2011 2:36 am 
Offline
CRE Legend
User avatar

Joined: Thu Jun 12, 2008 6:39 am
Posts: 2394
Location: New Zealand
rudolfl wrote:
Thanks,

I think you are right -- suhosinis plugin is in use. How does one decode session information when it is encrypted?

Thanks,
Rudolf

Don't think you can - your host would need to disable suhosin.session.encrypt ... as mentioned, doubt they would.

Simon

_________________
www.codemehappy.com
For Cre Loaded tips, how-to articles and more


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 4 posts ] 

Board index » Web Design and Development » Development Discussions

All times are UTC - 5 hours


Who is online

Users browsing this forum: No registered users and 1 guest


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
It is currently Thu May 17, 2012 8:48 am
Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group

© CRE Loaded is a product of Chain Reaction Ecommerce, Inc. Usage & Privacy Policy