# Login destroys session bug workaround

**URL:** <https://forum.getkirby.com/t/login-destroys-session-bug-workaround/5040>\
**Category:** Questions\
**Tags:** v2\
**Created:** [August 22, 2016, 5:51pm UTC](https://forum.getkirby.com/t/login-destroys-session-bug-workaround/5040 "2016-08-22T17:51:07Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![carstengrimm](https://dub1.discourse-cdn.com/flex017/user_avatar/forum.getkirby.com/carstengrimm/32/188_2.png) [@carstengrimm](https://forum.getkirby.com/u/carstengrimm)\
**Post date:** [August 22, 2016, 5:51pm UTC](https://forum.getkirby.com/t/login-destroys-session-bug-workaround/5040/1 "2016-08-22T17:51:07Z")

</div>

As reported here, i wonder if there is a workaround to keep other session values when logging in to front-end, as i encounter the problem:

> <https://github.com/getkirby/kirby/issues/408>
>
> I am using kirby and panel \`origin/develop\` but i can not get custom pageModels …to work. what am i missig? I assumed creating a template, blueprint and model named \*product\* should do the trick.
> I created a custom plugin with composer and psr-4 like your demo-plugin.
> 
> sidequestion: will the pageModel be loaded in the kirby 3 panel? kirby 2 did not do this without a little hack.
> 
> \*\*site/plugins/bnomei-product/config.php\*\*
> \`\`\`php
> Kirby::plugin(\[
> 'name' =\> 'bnomei/product',
> 'extends' =\> \[
> 'pageModels' =\> \[
> 'product' =\> Bnomei\\Model\\Product::class, // name of template, right?
> \],
> 'blueprints' =\> \[
> 'pages/product' =\> \_\_DIR\_\_ . '/blueprints/pages/product.yml',
> \],
> 'templates' =\> \[
> 'product' =\> \_\_DIR\_\_ . '/templates/product.php'
> \],
> \]
> \]);
> \`\`\`
> 
> \*\*site/plugins/bnomei-product/blueprints/pages/product.yml\*\*
> \`\`\`yml
> name: product # does this override the templatename based on filename if set to another string?
> title: Product
> sections:
> content:
> type: fields
> fields:
> text:
> label: Text
> type: textarea
> cover:
> extends: sections/image
> template: cover
> min: 1
> \`\`\`
> 
> \*\*site/plugins/bnomei-product/models/product.php\*\*
> \`\`\`php
> namespace Bnomei\\Model;
> 
> class Product extends Kirby\\Cms\\Page
> {
> public function test()
> {
> return $this-\>id();
> }
> }
> \`\`\`
> 
> \*\*site/plugins/bnomei-product/templates/product.php\*\*
> \`\`\`php
> echo Bnomei\\Model\\Product::class. ' ?= ' .get\_class($page); // Bnomei\\Model\\Product ?= Kirby\\Cms\\Page
> echo ' =\> \['.$page-\>id().' ?= '.$page-\>test().'\]'; // products/product-a ?=
> echo $page-\>template(); // product
> \`\`\`

is there anyone on it to change how the login works?

---

<div class="post-metadata">

**Author:** ![lukasbestle](https://dub1.discourse-cdn.com/flex017/user_avatar/forum.getkirby.com/lukasbestle/32/11437_2.png) [@lukasbestle](https://forum.getkirby.com/u/lukasbestle)\
**Post date:** [August 25, 2016, 3:32pm UTC](https://forum.getkirby.com/t/login-destroys-session-bug-workaround/5040/2 "2016-08-25T15:32:58Z")

</div>

Please see [this explanation over at OWASP](https://www.owasp.org/index.php/Session_Management_Cheat_Sheet#Renew_the_Session_ID_After_Any_Privilege_Level_Change). Not starting a new session on login is a security risk.

---

<div class="post-metadata">

**Author:** ![carstengrimm](https://dub1.discourse-cdn.com/flex017/user_avatar/forum.getkirby.com/carstengrimm/32/188_2.png) [@carstengrimm](https://forum.getkirby.com/u/carstengrimm)\
**Post date:** [August 25, 2016, 3:46pm UTC](https://forum.getkirby.com/t/login-destroys-session-bug-workaround/5040/3 "2016-08-25T15:46:36Z")

</div>

so i guess e.g. the shopping cart case we have to work around it for example saving the current cart to a cookie, when logging in filling the cookie into the session yet again?

or is there another way around to keep the information?

guess @samnabi is also interested.

---

<div class="post-metadata">

**Author:** ![lukasbestle](https://dub1.discourse-cdn.com/flex017/user_avatar/forum.getkirby.com/lukasbestle/32/11437_2.png) [@lukasbestle](https://forum.getkirby.com/u/lukasbestle)\
**Post date:** [August 25, 2016, 8:29pm UTC](https://forum.getkirby.com/t/login-destroys-session-bug-workaround/5040/4 "2016-08-25T20:29:06Z")

</div>

I guess Kirby _could_ copy over the session data to the new session, but I don’t know what @bastianallgeier’s motivation was to destroy the session completely on login. I have invited him to this topic.

---

<div class="post-metadata">

**Author:** ![bastianallgeier](https://dub1.discourse-cdn.com/flex017/user_avatar/forum.getkirby.com/bastianallgeier/32/7569_2.png) [@bastianallgeier](https://forum.getkirby.com/u/bastianallgeier)\
**Post date:** [August 26, 2016, 10:17am UTC](https://forum.getkirby.com/t/login-destroys-session-bug-workaround/5040/5 "2016-08-26T10:17:49Z")

</div>

Logging out first is basically a clean-up process to get rid of any data that might create conflicts. I think we could only clean up all panel session vars though and copy over the rest. That might probably work.

---

<div class="post-metadata">

**Author:** ![carstengrimm](https://dub1.discourse-cdn.com/flex017/user_avatar/forum.getkirby.com/carstengrimm/32/188_2.png) [@carstengrimm](https://forum.getkirby.com/u/carstengrimm)\
**Post date:** [August 26, 2016, 10:31am UTC](https://forum.getkirby.com/t/login-destroys-session-bug-workaround/5040/6 "2016-08-26T10:31:49Z")

</div>

so in an upcoming version of kirby, the login will not delete all sessions?

as for now i fixed the problem saving certain session values into a cookie and return the values into the session after logging in again. as in my case it’s no critical data involved i guess that’s fine for me, for now.

---

<div class="post-metadata">

**Author:** ![Thiousi](https://dub1.discourse-cdn.com/flex017/user_avatar/forum.getkirby.com/thiousi/32/13656_2.png) [@Thiousi](https://forum.getkirby.com/u/Thiousi)\
**Post date:** [August 26, 2016, 11:01am UTC](https://forum.getkirby.com/t/login-destroys-session-bug-workaround/5040/7 "2016-08-26T11:01:48Z")

</div>

Could you share the code you used to save the session values to the cookie and back? It would surely be useful for others 🙂 At least I could use it in one project where the sessions are not optimal at the moment 🙂

---

<div class="post-metadata">

**Author:** ![carstengrimm](https://dub1.discourse-cdn.com/flex017/user_avatar/forum.getkirby.com/carstengrimm/32/188_2.png) [@carstengrimm](https://forum.getkirby.com/u/carstengrimm)\
**Post date:** [August 26, 2016, 11:14am UTC](https://forum.getkirby.com/t/login-destroys-session-bug-workaround/5040/8 "2016-08-26T11:14:41Z")

</div>

sure:

Setting the Cookie on the Login Page

```auto
$shoppingcart = array();
      foreach($pages->find('shop')->children()->visible() as $session){
      if(s::get($session->uid())){
          $shoppingcart[] = array(
            'produkt' => $session->uid(),
            'qty' => s::get($session->uid()),
          );
          cookie::set('cart',json_encode($shoppingcart),60);
      }
  }

```

Return Cookie into the Session, and deleting the cookie again:

```auto
      if(cookie::get('cart')){
        $cookiecart = json_decode(cookie::get('cart'));
        foreach($cookiecart as $cartsession){
          s::set($cartsession->produkt, $cartsession->qty);
          cookie::remove('cart');
        }
      }

```

as short explaination:

i am using a session to save a shopping cart where as the page-\>uid is some kind of the identifier, and the session value e.g. 1, 2, 3 etc pp.

so in short i go though all products to see if there’s a session with that identifier, save the values into $shoppingcart encode it as json, and after logging in decode json and run each value into the session using the same identifiers obviously. lastly deleting the cookie again as it’s not needed anymore.

---

<div class="post-metadata">

**Author:** ![lukasbestle](https://dub1.discourse-cdn.com/flex017/user_avatar/forum.getkirby.com/lukasbestle/32/11437_2.png) [@lukasbestle](https://forum.getkirby.com/u/lukasbestle)\
**Post date:** [August 26, 2016, 12:34pm UTC](https://forum.getkirby.com/t/login-destroys-session-bug-workaround/5040/9 "2016-08-26T12:34:46Z")

</div>

Could you please test the [improved-login feature branch](https://github.com/getkirby/kirby/tree/feature/improved-login)? Should work, but we haven’t tested this enough yet to be merged.

---

<div class="post-metadata">

**Author:** ![distantnative](https://dub1.discourse-cdn.com/flex017/user_avatar/forum.getkirby.com/distantnative/32/11319_2.png) [@distantnative](https://forum.getkirby.com/u/distantnative)\
**Post date:** [February 6, 2025, 4:53pm UTC](https://forum.getkirby.com/t/login-destroys-session-bug-workaround/5040/10 "2025-02-06T16:53:15Z")

</div>


