Im using laravel to develoment an app. i need to store the session in database and everything works fine until i want to test in firefox.
When i Log in a user in Firefox, every request creates a new session row in database without the user_id. Session seems to working fine but im getting trash rows in every request.
Im getting a lot of trash rows here
This only happens in firefox, my cookies are enabled, i try it in other computers and getting the same results.
I already double checked my middlewares, config/session.php and .env files.
kernel.php
protected $middlewareGroups = [
'web' => [
\App\Http\Middleware\EncryptCookies::class,
\Illuminate\Cookie\Middleware\AddQueuedCookiesToResponse::class,
\Illuminate\Session\Middleware\StartSession::class,
\Illuminate\Session\Middleware\AuthenticateSession::class,
\Illuminate\View\Middleware\ShareErrorsFromSession::class,
\App\Http\Middleware\VerifyCsrfToken::class,
\Illuminate\Routing\Middleware\SubstituteBindings::class,
],
'api' => [
'throttle:60,1',
\Illuminate\Routing\Middleware\SubstituteBindings::class,
],
];
/**
* The application's route middleware.
*
* These middleware may be assigned to groups or used individually.
*
* @var array
*/
protected $routeMiddleware = [
'auth' => \App\Http\Middleware\Authenticate::class,
'auth.basic' => \Illuminate\Auth\Middleware\AuthenticateWithBasicAuth::class,
'bindings' => \Illuminate\Routing\Middleware\SubstituteBindings::class,
'cache.headers' => \Illuminate\Http\Middleware\SetCacheHeaders::class,
'can' => \Illuminate\Auth\Middleware\Authorize::class,
'guest' => \App\Http\Middleware\RedirectIfAuthenticated::class,
'password.confirm' => \Illuminate\Auth\Middleware\RequirePassword::class,
'signed' => \Illuminate\Routing\Middleware\ValidateSignature::class,
'throttle' => \Illuminate\Routing\Middleware\ThrottleRequests::class,
'verified' => \Illuminate\Auth\Middleware\EnsureEmailIsVerified::class,
'EscuelaEnPaquete'=>\App\Http\Middleware\EscuelaEnPaquete::class,
'SesionesUsuario'=>\App\Http\Middleware\SesionesUsuario::class,
];
'SesionesUsuario'
//Actualizamos la ultima interacción
$actualmenor = \Carbon\Carbon::now()->subSeconds(env('MAX_seconds_IS_ALIVE'))->timestamp;
$actual = \Carbon\Carbon::now()->timestamp;
$sesion = Session::where('id',\Session::getId())->where("user_id",Auth::id())->first();
if($sesion){
$sesion = Session::find(\Session::getId());
$sesion->last_activity = $actual;
if($sesion->login_on == null){
$sesion->login_on = $actual;
}
$sesion->save();
}
//checamos si existe sesion
$sesiones = Session::where("user_id",Auth::id())->where("id",'<>',\Session::getId())->count();
if($sesiones >= env('MAX_SESSIONS')){
//Camino: Eliminar sesion mas antigua
$take = env('MAX_SESSIONS')-1;
if(env('MAX_SESSIONS')-1 < 0){
$take = 0;
}
$sesion_eliminar = Session::selectRaw('id as id_session')->where("user_id",Auth::id())->where("id",'<>',\Session::getId())->orderBy('login_on','DESC')->take($take)->get();
$array_salvar_eliminar =[];
foreach ($sesion_eliminar as $ident){
array_push($array_salvar_eliminar,$ident->id_session);
}
array_push($array_salvar_eliminar,\Session::getId());
//Quitamos sesiones sobrantes
Session::where("user_id",Auth::id())->whereNotIn('id',$array_salvar_eliminar)->delete();
}
return $next($request);
The middleware is actually working, but i cant let the trash session in database.
UPDATE: ok, i do a deeper debug and the extra sessions are only added when an ajax call is made.
UPDATE: this happened in all browser but for weird reasons it only happened in firefox when i wrote this.
EDIT: edited the title to be more accurate.