如何从PHP向CodeIgniter同步SSO会话?
Hey there! Since you're new to CodeIgniter and already have an SSO setup in plain PHP, let's walk through practical steps to bridge those external PHP sessions into the CodeIgniter framework. Here's what you need to do:
CodeIgniter has its own session management system, so you need to make sure its session settings match your plain PHP SSO setup to avoid conflicts:
- Open
application/config/config.php- Set
$config['sess_cookie_name']to the same session name used in your plain PHP code (e.g., if your PHP SSO usesMY_SSO_SESSION, use that value here) - Match the session save path: If your plain PHP sessions are stored in a specific folder, set
$config['sess_save_path'] = '/path/to/your/shared/session/folder';(ensure the folder has proper read/write permissions) - Unify cookie domain for cross-subdomain SSO: Set
$config['cookie_domain'] = '.yourdomain.com';(the leading dot lets sessions work across subdomains likeapp.yourdomain.comandsso.yourdomain.com) - Disable CI's auto-session start: Set
$config['sess_auto_start'] = FALSE;—we'll handle session initialization manually.
- Set
Since we turned off CI's auto-session start, we'll initialize the plain PHP session first, then sync its data to CI's session store. The best place to do this is in a base controller (like MY_Controller) so all your CI controllers inherit this logic:
// application/core/MY_Controller.php class MY_Controller extends CI_Controller { public function __construct() { parent::__construct(); // Start the plain PHP session from your SSO session_start(); // Check if the user is logged in via your SSO if (isset($_SESSION['sso_user_id']) && !empty($_SESSION['sso_user_id'])) { // Sync critical SSO data to CodeIgniter's session $this->session->set_userdata([ 'user_id' => $_SESSION['sso_user_id'], 'username' => $_SESSION['sso_username'], 'sso_token' => $_SESSION['sso_token'] // Include any validation tokens here ]); } else { // Redirect to your SSO login page if no valid session exists redirect('https://your-sso-domain.com/login'); } } }
Then make all your CI controllers extend MY_Controller instead of CI_Controller—this ensures the session sync runs on every page load.
When the user logs out, you need to destroy both the CI session and the plain PHP SSO session to avoid leftover state:
// In your CI logout controller method public function logout() { // Destroy CodeIgniter's session $this->session->sess_destroy(); // Destroy the plain PHP SSO session session_start(); session_destroy(); unset($_SESSION); // Redirect to SSO logout page to complete the process redirect('https://your-sso-domain.com/logout'); }
Don't just trust the session data blindly—add a validation step to confirm the SSO session is legitimate. For example, if your SSO issues a signed token, verify it in CI:
// Inside MY_Controller's __construct if (isset($_SESSION['sso_token'])) { // Call your SSO's validation endpoint or use a secret key to verify the token $is_valid = $this->verify_sso_token($_SESSION['sso_token']); if (!$is_valid) { redirect('https://your-sso-domain.com/login'); } }
- Log in via your plain PHP SSO, then visit a CI page and dump session data to confirm sync works:
var_dump($this->session->userdata()); var_dump($_SESSION); - Test logout to ensure both sessions are cleared.
- Check cross-subdomain behavior if your SSO and CI app are on different subdomains.
内容的提问来源于stack exchange,提问作者alfakhri

