Here are the code of my login page where the login script checks for the authenticity of the user and then redirects to inbox page using header function.


// Some query processing on database    

if(($id_user_fetched<=$id_max_fetched) && ($id_user_fetched!=0)){
$_SESSION['loggedIn'] = 'yes';
    //echo 'Login Successful';
        echo 'Invalid Login';
        echo'<br /> <a href="index.html">Click here to try again</a>';
    echo mysqli_error("Login Credentials Incorrect!");

The inbox.php page looks like this:

echo 'SESSION ='.$_SESSION['loggedIn'];
if($_SESSION['loggedIn'] != 'yes'){
echo $message = 'you must log in to see this page.';


Now with the above code, the inbox.php always shows the output: SESSION=you must log in to see this page. Which means that either the session variable is not being setup or the inbox.php is unable to retrieve the session variable. Where am i going wrong?

  1. Make sure session_start(); is called before any sessions are being called. So a safe bet would be to put it at the beginning of your page, immediately after the opening <?php tag before anything else. Also ensure there are no whitespaces/tabs before the opening <?php tag.
  2. After the header redirect, end the current script using exit(); (Others have also suggested session_write_close(); and session_regenerate_id(true), you can try those as well, but I'd use exit();).
  3. Make sure cookies are enabled in the browser you are using to test it on.
  4. Ensure register_globals is off, you can check this on the php.ini file and also using phpinfo(). Refer to this as to how to turn it off.
  5. Make sure you didn't delete or empty the session.
  6. Make sure the key in your $_SESSION superglobal array is not overwritten anywhere.
  7. Make sure you redirect to the same domain. So redirecting from a to doesn't carry the session forward.
  8. Make sure your file extension is .php (it happens!).

I had the same issue for a while and had a very hard time figuring it out. My problem was that I had the site working for a while with the sessions working right, and then all of the sudden everything broke.

Apparently, your session_save_path(), for me it was /var/lib/php5/, needs to have correct permissions (the user running php, eg www-data needs write access to the directory). I accidentally changed it, breaking sessions completely.

Run sudo chmod -R 700 /var/lib/php5/ and then sudo chown -R www-data /var/lib/php5/ so that the php user has access to the folder.

Maybe if your session path is not working properly you can try session.save_path(path/to/any folder); function as alternative path. If it works you can ask your hosting provider about default path issue.

If you use a connection script, dont forget to use session_start(); at the connection too, had some trouble before noticing that issue.

Just talked to the hosting service, it was an issue at their end. he said " your account session.save_path was not set as a result issue arise. I set it for you now."

And it works fine after that :)

  • It should be echo "Login Credentials Incorrect!" ; not echo mysqli_error("Login Credentials Incorrect!");
  • Can you debug to confirm that the conditions of your if statement evaluates to true? (i.e echo a statement in the true and false block to see which one is firing)
  • 1. do you call both scripts from the same domain? 2. do you use any kind of session_name, session_id, session_set_cookie? 3. session_start returns value, do you check it?
  • @Crackertastic Yes i can assure you that they evaluate to true. checked several times
  • These are two else statements for one if
  • could it possibly be a server error? i tried the most basic test examples as under: session.php <?php session_start(); // store session data $_SESSION['views']=1; header('Location:session2.php'); ?> session2.php: <?php session_start(); //retrieve session data echo "Pageviews=". $_SESSION['views']; ?>
  • I have same problem. Cause: there was no free disk space!
  • same problem for me. i try to print the page using google cloud print but the session are closed/cleared. how to fix that
  • Regarding #4: This feature has been DEPRECATED as of PHP 5.3.0 and REMOVED as of PHP 5.4.0.
  • For me this problem is caused by no disk space, as Cuarculu. I suggest revo to add this cause in his list. Thanks
  • 777 is a bad set of permissions for the session save folder. You need to change the ownership of the folder to allow the web server to write to it and prevent all other access.
  • HOOOOLY SHIT man, all the best in your life, I was literally crying because I couldn't get session onto the next page.