PHP7.3.23+CI4.0.4:跳转至CCAvenue支付网关后会话数据丢失
Alright, let's break down exactly what's happening here and how to fix it.
What's Causing the Session Loss?
That console message Indicate whether to send a cookie in a cross-site request by specifying its SameSite attribute. is the key clue. When users are redirected to CCAvenue (a cross-site payment gateway) and then sent back to your app via the payment callback, this counts as a cross-site request.
By default, browsers use SameSite=Lax for cookies, which blocks them from being sent in cross-site requests. This is a security measure to prevent CSRF attacks and accidental data leaks, but it breaks legitimate flows like payment callbacks where you need to maintain the user's session.
Step-by-Step Fixes
Here are two reliable ways to adjust the SameSite cookie settings for your CodeIgniter 4 setup:
1. Update CodeIgniter 4's App Configuration
CodeIgniter 4 has built-in settings for session cookies, so this is the cleanest approach:
- Open
app/Config/App.phpin your project - Locate the
$sessionCookieSameSiteand$sessionCookieSecurevariables - Set
$sessionCookieSameSiteto'None'and$sessionCookieSecuretotrue(sinceSameSite=Nonerequires cookies to be secure, meaning HTTPS-only)
Your modified config should look like this:
public $sessionCookieSameSite = 'None'; public $sessionCookieSecure = true;
Important: If your site isn't running on HTTPS yet, you'll need to set that up first—otherwise, the secure cookie won't be saved by browsers.
2. Directly Modify PHP's INI Settings
If the CI4 config approach doesn't work (rare, but possible with older minor versions), you can override PHP's session cookie settings directly:
- Add these lines at the very top of your project's entry file (usually
public/index.php):
ini_set('session.cookie_samesite', 'None'); ini_set('session.cookie_secure', 1);
Alternatively, edit your server's php.ini file to make the change global:
session.cookie_samesite = None session.cookie_secure = 1
Verify the Fix
After making these changes, test the full payment flow:
- Initiate a payment from your app to CCAvenue
- Complete the payment process
- Check if your app successfully loads the user's session data after the callback
- Confirm the SameSite warning no longer appears in the browser console
内容的提问来源于stack exchange,提问作者Shoyeb

