PHP sessions: where they live, and why users get logged out

A PHP session is a small file on the server, tied to the visitor by a cookie (the PHPSESSID). That is where the application keeps who is logged in, what is in the basket, and so on. When a user is “logged out for no reason”, one of two things happened: the file disappeared, or the cookie stopped arriving.

The causes, from most to least common

Cause How to recognise it What to do
A short lifetime Logs out after a few idle minutes, but not in the middle of a task. PHP clears session files idle for longer than session.gc_maxlifetime, which by default is short. Raise it, and match the cookie’s lifetime in the application itself.
The PHP version changed Everybody was logged out at once, a single time. Normal: each PHP version keeps its sessions in its own folder. It does not happen again.
www and no www, or http and https Logged in on one address and logged out on the other. A cookie belongs to one address. Pick one and redirect the other. See .htaccess for PHP projects.
A cache serving logged-in pages One user sees another’s name, or is “logged out” only on some pages. The page cache (a plugin’s or a CDN’s) must exclude logged-in pages.
PHP cannot write the session A “Failed to write session data” warning, or sessions that never stick. The account’s space ran out, or the sessions folder lacks permission. Check the space in cPanel.
session_start() too late The “headers already sent” warning appears and the cookie is never sent. session_start() must run before any text goes out, including spaces before <?php. It is a bug in the code.

Giving your application a sessions folder of its own

This is only worth it if you need a different lifetime from the rest, or want sessions out of the default place. It is not needed day to day.

1 In the File Manager, create a folder outside the public folder, for example /home/YOURACCOUNT/sessions, and give it permission 700.
2 In the application’s folder, add the lines below to the .user.ini. See where to set each value.
3 Wait a few minutes, log in to the site and check that a new file appeared in the folder.

session.save_path = "/home/YOURACCOUNT/sessions"
session.gc_maxlifetime = 7200

The second value is in seconds and is an example.

Do not put the sessions folder inside public_html. A session file is a key to the front door: whoever can read it can act as that user.
“Keep me logged in” is an application feature, not a PHP one. It normally sets a second, long-lived cookie. If the application does not offer it, raising gc_maxlifetime as high as you like does not help: the session cookie dies when the browser closes.

Users are still being logged out and you have been through the table? Tell us the address and the time it happened.

Open a support ticket

SEE ALSO

php.ini and .user.ini: where to set a value

Where the PHP error log is

.htaccess for PHP projects: friendly URLs and redirects

Changing your PHP version without breaking the site

RECOMMENDED PRODUCT

Web hosting with cPanel

Domain and SSL included, daily backups and the panel you already know. from 321,75 MT/mo (3-year plan, with coupon)

See plans
  • 0 Users Found This Useful
Was this answer helpful?