<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
	<title type="html"><![CDATA[FrontAccounting forum — Session dropped behind Cloudflare (orange-cloud)]]></title>
	<link rel="self" href="https://frontaccounting.com/punbb/extern.php?action=feed&amp;tid=10741&amp;type=atom" />
	<updated>2026-09-27T20:50:37Z</updated>
	<generator>PunBB</generator>
	<id>https://frontaccounting.com/punbb/viewtopic.php?id=10741</id>
		<entry>
			<title type="html"><![CDATA[Session dropped behind Cloudflare (orange-cloud)]]></title>
			<link rel="alternate" href="https://frontaccounting.com/punbb/viewtopic.php?pid=43885#p43885" />
			<content type="html"><![CDATA[<p>FrontAccounting 2.4.20 on PHP 8.3, site published through Cloudflare with the proxy on (orange cloud).</p><p>Problem:<br />The login was dropped every few screens, and in particular each time a main-menu tab was opened (index.php?application=...). Logging in again worked, until the next tab.</p><p>SessionManager stores the client address on the session and, in preventHijacking(), treats a different address as a hijack and wipes the session. Behind Cloudflare, REMOTE_ADDR is a Cloudflare edge address, and that address changes from one request to the next. The visitor has not changed. The next menu click looks like a hijack, and the login is cleared.</p><p>Solution:<br />I enabled a solution that works for all users as it currently does, but also for servers who use Cloudflare Orange.</p><p>What I changed:<br />1. The address stored and compared is the visitor address Cloudflare sends (CF-Connecting-IP), and only when the request also has Cloudflare&#039;s CF-RAY header. Both headers are required so a client who simply sends CF-Connecting-IP is not trusted.<br />Users who are not coming through Cloudflare orange-cloud, or through another proxy that sets those two headers, are not affected. A LAN client, or a WAN client hitting the server directly, has no CF-RAY header, so clientAddress() returns REMOTE_ADDR and the check is the same as before.</p><p>2. I removed the 5% random call to regenerateSession() on every request. That path is not specific to Cloudflare. On PHP 8, regenerateSession() (session_regenerate_id, session_write_close, then session_start again) drops the logged-in session on the requests where it runs. A real address mismatch still calls regenerateSession().</p><p>Code:<br />------<br />Replaced, in sessionStart():<br />$_SESSION[&#039;IPaddress&#039;] = $_SERVER[&#039;REMOTE_ADDR&#039;];</p><p>with:<br />$_SESSION[&#039;IPaddress&#039;] = $this-&gt;clientAddress();</p><p>------</p><p>Removed, immediately after regenerateSession() in that same block:<br />// Give a 5% chance of the session id changing on any request<br />}<br />elseif (rand(1, 100) &lt;= 5)<br />{<br />&nbsp; &nbsp; $this-&gt;regenerateSession();<br />}</p><p>------</p><p>Replaced, in preventHijacking():<br />if ($_SESSION[&#039;IPaddress&#039;] != $_SERVER[&#039;REMOTE_ADDR&#039;])<br />&nbsp; &nbsp; return false;</p><p>with:</p><p>if ($_SESSION[&#039;IPaddress&#039;] != $this-&gt;clientAddress())<br />&nbsp; &nbsp; return false;</p><p>------</p><p>Added, immediately above preventHijacking():<br />// Visitor address. Cloudflare&#039;s own address changes between requests, so the<br />// session is kept against CF-Connecting-IP when that request came through Cloudflare.<br />function clientAddress()<br />{<br />&nbsp; &nbsp; if (!empty($_SERVER[&#039;HTTP_CF_CONNECTING_IP&#039;]) &amp;&amp; !empty($_SERVER[&#039;HTTP_CF_RAY&#039;]))<br />&nbsp; &nbsp; &nbsp; &nbsp; return $_SERVER[&#039;HTTP_CF_CONNECTING_IP&#039;];<br />&nbsp; &nbsp; return isset($_SERVER[&#039;REMOTE_ADDR&#039;]) ? $_SERVER[&#039;REMOTE_ADDR&#039;] : &#039;&#039;;<br />}</p><p>------<br />After this, one fresh login stays put across the menu tabs. I&#039;m happy for this to be adjusted if there is a preferred way to handle it in the next release.</p>]]></content>
			<author>
				<name><![CDATA[DiggerNZ]]></name>
				<uri>https://frontaccounting.com/punbb/profile.php?id=48877</uri>
			</author>
			<updated>2026-09-27T20:50:37Z</updated>
			<id>https://frontaccounting.com/punbb/viewtopic.php?pid=43885#p43885</id>
		</entry>
</feed>
