CodeIgniter跨子域名多应用会话共享可行性及实现方案咨询
Absolutely feasible! Let me walk you through exactly how to make this work with your subdomain setup and CodeIgniter project structure.
First, Pick the Right Session Storage Method
You can’t use CodeIgniter’s default file-based sessions for cross-subdomain sharing—file sessions are tied to a single server directory and won’t be accessible across different subdomain apps. The best approach here is to use database-stored sessions, so all your applications can read/write from the same session dataset.
Step 1: Set Up the Session Database Table (All Apps)
First, create a dedicated table for sessions in your database. CodeIgniter provides a ready-to-use SQL script, or you can run this directly:
CREATE TABLE IF NOT EXISTS `ci_sessions` ( `id` varchar(128) NOT NULL, `ip_address` varchar(45) NOT NULL, `timestamp` int(10) unsigned DEFAULT 0 NOT NULL, `data` blob NOT NULL, PRIMARY KEY (id), KEY `ci_sessions_timestamp` (`timestamp`) );
Then, update the session config in every application’s application/config/config.php to use the database driver:
$config['sess_driver'] = 'database'; $config['sess_cookie_name'] = 'ci_session'; // We'll tweak this for admins later $config['sess_expiration'] = 7200; // Adjust to your preferred session timeout $config['sess_save_path'] = 'ci_sessions'; // Match the table name you just created $config['sess_match_ip'] = FALSE; // Critical for subdomains—turn this off, or sessions will break between subdomains $config['sess_time_to_update'] = 300; $config['sess_regenerate_destroy'] = FALSE;
Share Sessions Between Client Websites (application1/client & application2/client)
For your client-facing subdomains, you need to make sure cookies are accessible across all client subdomains. Here’s what to do:
- In both client apps’
application/config/config.php, set the cookie domain to your root domain (with a leading dot to cover all subdomains):
$config['cookie_domain'] = '.yourmaindomain.com'; // e.g., if your root is example.com, use .example.com $config['cookie_path'] = '/'; $config['cookie_secure'] = FALSE; // Switch to TRUE if you're using HTTPS $config['cookie_httponly'] = TRUE; // Adds a layer of security against XSS
- Make sure both client apps use the exact same encryption key in
config.php:
$config['encryption_key'] = 'your-shared-encryption-key-here';
CodeIgniter encrypts session data, so mismatched keys will prevent apps from reading each other’s sessions.
Share Sessions Between Admin Websites (application1/admin & application3/admin)
The logic is similar to client apps, but we’ll use a separate cookie to keep admin sessions isolated from client sessions (safer and cleaner):
- In both admin apps’
application/config/config.php, tweak the session and cookie settings:
// Use a unique cookie name for admins to avoid conflicts with clients $config['sess_cookie_name'] = 'ci_admin_session'; // Same root domain for cookies $config['cookie_domain'] = '.yourmaindomain.com'; $config['cookie_path'] = '/'; $config['cookie_secure'] = FALSE; // TRUE for HTTPS $config['cookie_httponly'] = TRUE;
- Again, ensure both admin apps share the same encryption key (this can be different from the client apps’ key for better security).
Quick Notes for Your Directory Structure
- Since you’re using a shared
systemdirectory, double-check that all applications are using this same system folder—version mismatches between CodeIgniter installations can break session parsing. - If any of your apps are on older CodeIgniter versions, consider upgrading them all to the same stable release to avoid compatibility bugs.
- When testing, clear your browser’s existing cookies first—old domain-locked cookies can interfere with your new setup.
Pro Tip: If you want complete separation between client and admin session data, you can create a second session table (e.g.,
ci_admin_sessions) and update thesess_save_pathconfig for admin apps to point to this table.
内容的提问来源于stack exchange,提问作者MUHAMMAD SIDDIQ

