PHP中$_REQUEST无法获取Cookie及登录跳转后失效问题求助
Hey there! Let's break down why you're having trouble accessing cookies via $_REQUEST after logging in and redirecting to show_user.php—I'll walk through the most common causes and fixes:
1. PHP config is excluding cookies from $_REQUEST
By default, $_REQUEST combines data from $_GET, $_POST, and $_COOKIE—but this behavior depends on two php.ini settings:
request_order: Determines the merge order. If it's set toGP(only GET/POST) instead ofGPC, cookies won't show up in$_REQUEST.variables_order: Another related setting that needs to includeC(for cookies) to populate the global cookie pool.
Fixes:
- Check your php.ini and set these to include
C, e.g.,request_order = "GPC"orvariables_order = "EGPCS". - If you can't edit php.ini, skip
$_REQUESTentirely and use$_COOKIEdirectly—it's more reliable for cookie-specific data and avoids config-dependent behavior.
2. Your cookie was set with incorrect parameters
If the cookie's path, domain, or security settings are off, it won't be sent to show_user.php:
- Path mismatch: If you set the cookie with
path="/signin"during login, it will only be accessible under the/signindirectory. Setpath="/"instead to make it available across your entire site. - Domain issues: If your login page is on a subdomain (e.g.,
auth.yoursite.com) andshow_user.phpis on the main domain, you need to setdomain=".yoursite.com"to let the cookie cross subdomains. - Secure/Httponly notes:
httponlyblocks JavaScript from reading cookies but doesn't affect PHP's$_COOKIE. If your site uses HTTPS, ensuresecure=trueso browsers only send the cookie over encrypted connections.
Example of a properly set cookie:
// Login success: set a cookie valid for 24h, accessible site-wide setcookie("user_session", $session_id, time() + 86400, "/", "", false, false);
3. You didn't terminate the script after redirecting
When you call header("Location: show_user.php") right after setting a cookie, you must add exit() or die() immediately after. Without this, PHP might continue executing code, which can corrupt the response headers and prevent the cookie from being saved by the browser.
Wrong way:
setcookie("user_id", $user_id); header("Location: show_user.php"); // Script keeps running—response headers might break
Right way:
setcookie("user_id", $user_id, time() + 86400, "/"); header("Location: show_user.php"); exit(); // Critical: stops script execution to ensure headers are sent correctly
4. Name conflicts between cookies and GET/POST data
If your cookie shares a name with a GET or POST parameter (e.g., both named user_id), $_REQUEST will prioritize the value from $_GET or $_POST (depending on request_order), overwriting the cookie value. Using $_COOKIE['your_cookie_name'] avoids this ambiguity entirely.
- After setting the cookie in
signin.php, immediately printvar_dump($_COOKIE)to confirm the cookie was set correctly. - In
show_user.php, print bothvar_dump($_COOKIE)andvar_dump($_REQUEST)to compare—if the cookie exists in$_COOKIEbut not$_REQUEST, it's a config issue. - Check your browser's dev tools (Application > Cookies) to verify the cookie is stored, and that its path/domain matches the URL of
show_user.php.
内容的提问来源于stack exchange,提问作者Shanojan.A

