RC7 cookie issues

Get help with installation and running phpBB 3.0.x here. Please do not post bug reports, feature requests, or MOD-related questions here.
Get Involved
Forum rules
END OF SUPPORT: 1 January 2017 (announcement)
Locked
User avatar
soadlink
Registered User
Posts: 39
Joined: Thu Jun 26, 2003 1:29 am

RC7 cookie issues

Post by soadlink » Tue Oct 16, 2007 12:25 am

Hello,

I am running RC7, and everything seems to be fine now, but I keep getting logged out even when I check "Log me on automatically each visit". I can close the browser, open it back up, and still be logged in. But it seems to just randomly log me out. At first I thought maybe it was a fluke and let it go, but it just did it again. I am using Firefox 2.0.0.7, but I think this may be a board wide issue.

I remember when it did this before (while using phpbbv2), I had to run auto cookies, but that was a mod for only phpbbv2. The feature did work fine until RC7 (could have started at RC6 too, but I dont know because I went directly from RC5 to RC7).

Here are the settings in my General > Cookie Settings:
Cookie domain: .hlss.us
Cookie name: phpbb3_5535v
Cookie path: /
Cookie secure: Disabled

General information:
Your board's URL: http://forums.hlss.us
Version of phpBB3: RC7
Was this a fresh install or a(n) update/upgrade/conversion (please be specific)? auto upgraded from RC5
Was this an install through your host? No
MODs you have installed: None
When the problem started: After going from RC5 to RC7
Template(s) used: Only the 2 official templates are enabled
Version of PHP used: 4.4.6
Database and version used: Mysql 4.1.22-standard

weber_
Registered User
Posts: 36
Joined: Wed Aug 22, 2007 9:24 am
Location: Lviv, Ukraine

Re: RC7 cookie issues

Post by weber_ » Tue Oct 16, 2007 12:58 am

Check what you have under ACP -> General -> Security Settings.

User avatar
soadlink
Registered User
Posts: 39
Joined: Thu Jun 26, 2003 1:29 am

Re: RC7 cookie issues

Post by soadlink » Tue Oct 16, 2007 1:04 am

weber_ wrote:Check what you have under ACP -> General -> Security Settings.
All appears to be fine there, here are the settings:

Allow persistent logins: Yes
Persistent login key expiration length (in days): 0
Session IP validation: a.b.c
Validate browser: Yes
Validated X_FORWARDED_FOR header: No
Check IP against DNS Blackhole List: No
Check e-mail domain for valid MX record: Yes
Password complexity: No requirements
Force password change: 0
Maximum number of login attempts: 3
Allow php in templates: No
Maximum time to submit forms: 7200
Minimum time to submit forms: 0
Tie forms to guest sessions: Yes

Edit: In General > Server settings, the script path is set to: /forum

But my forum path is: hlss.us/forums, so I have changed the script path to '/forums' instead of '/forum'. Not sure why this was set that way, or if I should have kept it that way, but could this be the problem?

weber_
Registered User
Posts: 36
Joined: Wed Aug 22, 2007 9:24 am
Location: Lviv, Ukraine

Re: RC7 cookie issues

Post by weber_ » Tue Oct 16, 2007 2:19 am

No, I think script path is not the problem.
Try to disable Session IP validation.

User avatar
soadlink
Registered User
Posts: 39
Joined: Thu Jun 26, 2003 1:29 am

Re: RC7 cookie issues

Post by soadlink » Tue Oct 16, 2007 4:02 am

Alright, I will try that.. but it has always been A.B.C before and I never had problems.

User avatar
wmtipton
Registered User
Posts: 564
Joined: Thu Apr 26, 2007 8:16 pm
Contact:

Re: RC7 cookie issues

Post by wmtipton » Tue Oct 16, 2007 5:08 am

weber_ wrote:No, I think script path is not the problem.
Try to disable Session IP validation.
Ive been having log out issues as well, on and off.
What we do when it happens is clear all browser cookies and 'delete all board cookies' and then it works again for a while.

If I disable session IP validation does that increase any 'risks' or cause any problems?
I mean, its there for a reason, right?
What the result of not having it enabled?

thanks
:)
mysql database backup software - mysql Workbench

CosmicD
Registered User
Posts: 67
Joined: Sat Jan 18, 2003 11:31 pm

Re: RC7 cookie issues

Post by CosmicD » Sat Oct 20, 2007 5:29 pm

i manage a board, upgraded to rc7 as well and I've got the same problem. I deleted board cookies, my settings arn't different from rc5 and everyone just gets kicked out: which is very annoying.

t-p
Registered User
Posts: 311
Joined: Wed Jun 13, 2007 12:51 am
Location: California, USA

Re: RC7 cookie issues

Post by t-p » Sun Oct 21, 2007 12:10 am

hi,

I am evaluating RC7, Prosilver. I experience the same issue as Saodlink. Here is my setting;

Session IP validation: a.b
Validate browser: Yes

In past, I also tried Session IP validation: a.b.c
NO change. In fact I experience this problem since RC1!!

--tp

User avatar
wmtipton
Registered User
Posts: 564
Joined: Thu Apr 26, 2007 8:16 pm
Contact:

Re: RC7 cookie issues

Post by wmtipton » Sun Oct 21, 2007 1:31 am

CosmicD wrote:i manage a board, upgraded to rc7 as well and I've got the same problem. I deleted board cookies, my settings arn't different from rc5 and everyone just gets kicked out: which is very annoying.
I actually just got a PM from one of our members who used PMs on another board we both go to and she said shes pretty much given up on our forum soley because she keeps getting logged out and its aggrivating when it happens as shes trying to post.

Ive tried changing just about everything so far and for some reason it does still do it at random times.
It didnt just start with RC7 for us tho, I think RC5 was when it began.
mysql database backup software - mysql Workbench

jayzer34
Registered User
Posts: 25
Joined: Sun Jun 17, 2007 2:00 am

Re: RC7 cookie issues

Post by jayzer34 » Sun Oct 21, 2007 3:27 am

My users are having the same cookie issues. It is quite frustrating.

bgawboy
Registered User
Posts: 4
Joined: Sun Mar 13, 2005 4:33 am

Re: RC7 cookie issues

Post by bgawboy » Sun Oct 21, 2007 5:23 pm

OK. I think I just solved part of a similar problem. Persistent login wasn't working and I noticed that the forum was not storing cookies at all. I checked my cookies in both Firefox and Safari, and noticed that my style cookie was being saved but no others. I also noticed that the style cookie had a different domain than the one I had it set up to use.

I had to make sure that the Cookie domain under Cookie settings was an exact match to the domain users typically use to access the forum. Ie, I used an aliased domain name in the move to test RC5/7 and it didn't work.

For my forum, most users access by going to the subdomain I set up through Apache, eg forum.example.com, rather than http://www.example.com/forum, or http://www.exampleforumalias.com. So, I had to change my cookie domain to exactly how it was accessed, .forum.example.com.

Since I was also struggling with debugging this situation, and didn't know exactly if they were related to the issue, I set most of my security settings off, such as
Session IP validation None
Validate Browser No

So, it may be now that I need to try turning them on one at a time, to see if there are other related issues with consistency of persistence.

Locked

Return to “[3.0.x] Support Forum”