

本文介绍了为什么会出现此PHP session_start()错误?的处理方法,对大家解决问题具有一定的参考价值,需要的朋友们下面随着小编来一起学习吧!



I can not figure out why I am getting this session error...


As far as I knew this happens only when there is some sort of output to the browser before the session_start() function is called, in this case there is nothing printed to screen before the call, not even any white space. Any ideas why I would still get the errors?


I posted the full source code of this demo so you can see exactly what I used to create the error.


$formKey = new formKey();

$error = 'No error';

//Is request?
if($_SERVER['REQUEST_METHOD'] == 'post')
    //Validate the form key
    if(!isset($_POST['form_key']) || !$formKey->validate())
        //Form key is invalid, show an error
        $error = 'Form key error!';
        //Do the rest of your validation here
        $error = 'No form key error!';

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
    <meta http-equiv="content-type" content="text/html;charset=UTF-8" />
    <title>Securing forms with form keys</title>
    <div><?php if($error) { echo($error); } ?>
    <form action="" method="post">
        <?php $formKey->outputKey(); ?>

        <dt><label for="username">Username:</label></dt>
        <dd><input type="text" name="username" id="username" /></dd>
        <dt><label for="username">Password:</label></dt>
        <dd><input type="password" name="password" id="password" /></dd>
        <dd><input type="submit" value="Submit" /></dd>


class formKey
    //Here we store the generated form key
    private $formKey;

    //Here we store the old form key
    private $old_formKey;

    //The constructor stores the form key (if one excists) in our class variable
    function __construct()
        //We need the previous key so we store it
            $this->old_formKey = $_SESSION['form_key'];

    //Function to generate the form key
    private function generateKey()
        $ip = $_SERVER['REMOTE_ADDR'];
        $uniqid = uniqid(mt_rand(), true);
        return md5($ip . $uniqid);

    //Function to output the form key
    public function outputKey()
        //Generate the key and store it inside the class
        $this->formKey = $this->generateKey();
        //Store the form key in the session
        $_SESSION['form_key'] = $this->formKey;

        //Output the form key
        echo "<input type='hidden' name='form_key' id='form_key' value='".$this->formKey."' />";

    //Function that validated the form key POST data
    public function validate()
        //We use the old formKey and not the new generated version
        if($_POST['form_key'] == $this->old_formKey)
            //The key is valid, return true.
            return true;
            //The key is invalid, return false.
            return false;



At this point, I am thinking that session_start() is throwing an error before it can get the cookie sent. An early error would get sent to the browser and prevent the cookie from being sent. However, in this case, you should see the earlier error on your screen. I know this is probably not the issue, but I can't think of what else could be causing the problem.

这篇关于为什么会出现此PHP session_start()错误?的文章就介绍到这了,希望我们推荐的答案对大家有所帮助,也希望大家多多支持!

09-05 19:55