<?xml version="1.0" encoding="UTF-8" ?>
<rss version="2.0">
<channel>
<title><![CDATA[Snooda]]></title> 
<link>http://www.snooda.com/index</link> 
<description><![CDATA[Snooda's Blog]]></description> 
<language>zh-cn</language> 
<copyright><![CDATA[Snooda]]></copyright>
<item>
<link>http://www.snooda.com/read/334</link>
<title><![CDATA[增加https登陆保护及子域名跨域共享session]]></title> 
<author>snooda &lt;admin@snooda.com&gt;</author>
<category><![CDATA[Blog事件]]></category>
<pubDate>Wed, 22 Jan 2014 17:36:34 +0000</pubDate> 
<guid>http://www.snooda.com/read/334</guid> 
<description>
<![CDATA[ 
	&nbsp;&nbsp;&nbsp;&nbsp;很久没写blog了。今天考虑写一篇，登陆过程中想起目前登陆还是http裸奔状态，安全性实在是差。决定加一个登陆https保护。<br/><br/>&nbsp;&nbsp;&nbsp;&nbsp;之前搞过一个startssl的免费证书，一年到期了。这次不想用他家了，一副浓浓山寨风。去namecheap搞了一个，很快就签发了。<br/><br/>&nbsp;&nbsp;&nbsp;&nbsp;给一个子域名部署上去，把博客登陆提交地址改成https地址。这样密码的提交操作就被https保护了。<br/><br/><br/>&nbsp;&nbsp;&nbsp;&nbsp; 如果只这么做了，登陆是不会成功的。因为子域的session和主域session默认是不通的。<br/><br/>&nbsp;&nbsp;&nbsp;&nbsp; 在session_start前加一句：&nbsp;&nbsp;ini_set("session.cookie_domain", '.snooda.com');<br/><br/><br/>&nbsp;&nbsp;&nbsp;&nbsp; 然后重启一下浏览器（此步骤必须）<br/><br/><br/>&nbsp;&nbsp;&nbsp;&nbsp; 尝试一下登陆，ok了。<br/>Tags - <a href="http://www.snooda.com/tags/session/" rel="tag">session</a>
]]>
</description>
</item><item>
<link>http://www.snooda.com/read/334#blogcomment157</link>
<title><![CDATA[[评论] 增加https登陆保护及子域名跨域共享session]]></title> 
<author>f you &lt;admin@fuck.io&gt;</author>
<category><![CDATA[评论]]></category>
<pubDate>Thu, 26 May 2016 02:26:59 +0000</pubDate> 
<guid>http://www.snooda.com/read/334#blogcomment157</guid> 
<description>
<![CDATA[ 
	
]]>
</description>
</item>
</channel>
</rss>