<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
	<channel>
		<title><![CDATA[FrontAccounting forum — Session dropped behind Cloudflare (orange-cloud)]]></title>
		<link>https://frontaccounting.com/punbb/viewtopic.php?id=10741</link>
		<atom:link href="https://frontaccounting.com/punbb/extern.php?action=feed&amp;tid=10741&amp;type=rss" rel="self" type="application/rss+xml" />
		<description><![CDATA[The most recent posts in Session dropped behind Cloudflare (orange-cloud).]]></description>
		<lastBuildDate>Sun, 27 Sep 2026 20:50:37 +0000</lastBuildDate>
		<generator>PunBB</generator>
		<item>
			<title><![CDATA[Session dropped behind Cloudflare (orange-cloud)]]></title>
			<link>https://frontaccounting.com/punbb/viewtopic.php?pid=43885#p43885</link>
			<description><![CDATA[<p>FrontAccounting 2.4.20 on PHP 8.3, site published through Cloudflare with the proxy on (orange cloud).</p><p>Problem:<br />The login was dropped every few screens, and in particular each time a main-menu tab was opened (index.php?application=...). Logging in again worked, until the next tab.</p><p>SessionManager stores the client address on the session and, in preventHijacking(), treats a different address as a hijack and wipes the session. Behind Cloudflare, REMOTE_ADDR is a Cloudflare edge address, and that address changes from one request to the next. The visitor has not changed. The next menu click looks like a hijack, and the login is cleared.</p><p>Solution:<br />I enabled a solution that works for all users as it currently does, but also for servers who use Cloudflare Orange.</p><p>What I changed:<br />1. The address stored and compared is the visitor address Cloudflare sends (CF-Connecting-IP), and only when the request also has Cloudflare&#039;s CF-RAY header. Both headers are required so a client who simply sends CF-Connecting-IP is not trusted.<br />Users who are not coming through Cloudflare orange-cloud, or through another proxy that sets those two headers, are not affected. A LAN client, or a WAN client hitting the server directly, has no CF-RAY header, so clientAddress() returns REMOTE_ADDR and the check is the same as before.</p><p>2. I removed the 5% random call to regenerateSession() on every request. That path is not specific to Cloudflare. On PHP 8, regenerateSession() (session_regenerate_id, session_write_close, then session_start again) drops the logged-in session on the requests where it runs. A real address mismatch still calls regenerateSession().</p><p>Code:<br />------<br />Replaced, in sessionStart():<br />$_SESSION[&#039;IPaddress&#039;] = $_SERVER[&#039;REMOTE_ADDR&#039;];</p><p>with:<br />$_SESSION[&#039;IPaddress&#039;] = $this-&gt;clientAddress();</p><p>------</p><p>Removed, immediately after regenerateSession() in that same block:<br />// Give a 5% chance of the session id changing on any request<br />}<br />elseif (rand(1, 100) &lt;= 5)<br />{<br />&nbsp; &nbsp; $this-&gt;regenerateSession();<br />}</p><p>------</p><p>Replaced, in preventHijacking():<br />if ($_SESSION[&#039;IPaddress&#039;] != $_SERVER[&#039;REMOTE_ADDR&#039;])<br />&nbsp; &nbsp; return false;</p><p>with:</p><p>if ($_SESSION[&#039;IPaddress&#039;] != $this-&gt;clientAddress())<br />&nbsp; &nbsp; return false;</p><p>------</p><p>Added, immediately above preventHijacking():<br />// Visitor address. Cloudflare&#039;s own address changes between requests, so the<br />// session is kept against CF-Connecting-IP when that request came through Cloudflare.<br />function clientAddress()<br />{<br />&nbsp; &nbsp; if (!empty($_SERVER[&#039;HTTP_CF_CONNECTING_IP&#039;]) &amp;&amp; !empty($_SERVER[&#039;HTTP_CF_RAY&#039;]))<br />&nbsp; &nbsp; &nbsp; &nbsp; return $_SERVER[&#039;HTTP_CF_CONNECTING_IP&#039;];<br />&nbsp; &nbsp; return isset($_SERVER[&#039;REMOTE_ADDR&#039;]) ? $_SERVER[&#039;REMOTE_ADDR&#039;] : &#039;&#039;;<br />}</p><p>------<br />After this, one fresh login stays put across the menu tabs. I&#039;m happy for this to be adjusted if there is a preferred way to handle it in the next release.</p>]]></description>
			<author><![CDATA[null@example.com (DiggerNZ)]]></author>
			<pubDate>Sun, 27 Sep 2026 20:50:37 +0000</pubDate>
			<guid>https://frontaccounting.com/punbb/viewtopic.php?pid=43885#p43885</guid>
		</item>
	</channel>
</rss>
