Varnish 破坏了 php 会话

Varnish 破坏了 php 会话

我有一个大项目,我们决定注入 varnish 缓存。经过多次编辑,我们将其注入实时服务器。一切都很顺利,但大约 8 小时后,用户开始抱怨他们使用自己的电子邮件密码登录,却变成了另一个用户!

我们决定删除所有会话缓存并重新启动 varnish 和 nginx,但有时用户仍会抱怨。

那么问题是:Varnish 怎么会破坏 php 会话?这种情况是怎么发生的?


vcl 4.0;

acl invalidators {

backend modniyostrov {
    .host = "";
    .port = "8080";


sub vcl_recv {

        if (req.method == "POST") {
            return (pass);

        if (req.url ~ "/administration/?.*" ||
            req.url ~ "/app_dev.php/?.*" ||
            req.url ~ "/account/?.*" ||
            req.url ~ "/cart/?.*" ||
            req.url ~ "/currency/?.*" ||
            req.url ~ "/login_check/?.*" ||
            req.url ~ "/login/?.*" 
            req.url ~ "/logout/?.*" 

         ) {
              return (pass);

        if (req.http.Cookie) {
            set req.http.Cookie = ";" + req.http.Cookie;
            set req.http.Cookie = regsuball(req.http.Cookie, "; +", ";");
            set req.http.Cookie = regsuball(req.http.Cookie, ";(ProductsViewMode|PHPSESSID|currency|APP_REMEMBER_ME|recentViews|mobile)=", "; \1=");
            set req.http.Cookie = regsuball(req.http.Cookie, ";[^ ][^;]*", "");
            set req.http.Cookie = regsuball(req.http.Cookie, "^[; ]+|[; ]+$", "");

            if (req.http.Cookie == "") {
                unset req.http.Cookie;

        #all pictures cache by 15 minutes
        if (req.url ~ "^.*\.(png|jp[e]?g|gif|swf|css|js|svg)?(\?v=.*)?$") {
            unset req.http.Cookie;
    #        set req.ttl = 900s;
            return (hash);

        #clear all cache content

        if (req.method == "PURGE") {
            if (!client.ip ~ invalidators) {
                return (synth(405, "Not allowed"));
            return (purge);

    #clear by ban system, particulary by taggs; see FOSHttpCacheBundle
       if (req.method == "BAN") {

        if (!client.ip ~ invalidators) {
            return (synth(405, "Not allowed"));

        # find
        if (req.http.X-Cache-Tags) {
            ban("obj.http.X-Host ~ " + req.http.X-Host
                + " && obj.http.X-Url ~ " + req.http.X-Url
                + " && obj.http.content-type ~ " + req.http.X-Content-Type
                + " && obj.http.X-Cache-Tags ~ " + req.http.X-Cache-Tags
        } else {
            ban("obj.http.X-Host ~ " + req.http.X-Host
                + " && obj.http.X-Url ~ " + req.http.X-Url
                + " && obj.http.content-type ~ " + req.http.X-Content-Type

        return (synth(200, "Banned"));

    # Add a Surrogate-Capability header to announce ESI support.
#    set req.http.Surrogate-Capability = "abc=ESI/1.0";

    return (hash);

    sub vcl_hash {

        #unset req.http.Cookie;

        set req.http.X-Have-To-Hash = ";" + req.http.Cookie;
        set req.http.X-Have-To-Hash = regsuball(req.http.X-Have-To-Hash, "; +", ";");
        set req.http.X-Have-To-Hash = regsuball(req.http.X-Have-To-Hash, ";(ProductsViewMode|currency|recentViews|mobile)=", "; \1=");
        set req.http.X-Have-To-Hash = regsuball(req.http.X-Have-To-Hash, ";[^ ][^;]*", "");
        set req.http.X-Have-To-Hash = regsuball(req.http.X-Have-To-Hash, "^[; ]+|[; ]+$", "");

        if (req.http.Cookie ~ "APP_REMEMBER_ME") {
            set req.http.X-Have-User = "true";
        } else {
            set req.http.X-Have-User = "false";


        return (lookup);


    sub vcl_backend_response {

        #for ban some objects
        set beresp.http.X-Url = bereq.url;
        set beresp.http.X-Host =;

        if (beresp.http.Cache-Control ~ "private" ||
            beresp.http.Cache-Control ~ "no-cache" ||
            beresp.http.Cache-Control ~ "no-store"
        ) {
            set beresp.ttl = 1h;
    #        set beresp.uncacheable = true;
            unset beresp.http.Cache-Control;

        if (beresp.http.X-Url ~ "^.*\.(png|jp[e]?g|gif|swf|css|js|svg)?(\?v=.*)?$") {
            set beresp.ttl = 24h;

        if (beresp.status == 502 || beresp.status == 404 || beresp.http.X-Cache-Debug) {
            set beresp.ttl = 0s;

    return (deliver);

    # Check for ESI acknowledgement and remove Surrogate-Control header
#    if (beresp.http.Surrogate-Control ~ "ESI/1.0") {
#        unset beresp.http.Surrogate-Control;
#        set beresp.do_esi = true;
#    }


sub vcl_deliver {

#     if (!resp.http.X-Cache-Debug) {
        # Remove ban-lurker friendly custom headers when delivering to client
       # unset resp.http.X-Url;
       # unset resp.http.X-Host;
       # unset resp.http.X-Cache-Tags;
#    } else {
        if (resp.http.X-Varnish ~ " ") {
            set resp.http.X-Cache = "HIT";
#            set resp.http.X-Cache-Hits = obj.hits;
        } else {
            set resp.http.X-Cache = "MISS";

#    }




if (beresp.http.Cache-Control ~ "private" ||
        beresp.http.Cache-Control ~ "no-cache" ||
        beresp.http.Cache-Control ~ "no-store"
    ) {
        set beresp.ttl = 1h;
#        set beresp.uncacheable = true;
        unset beresp.http.Cache-Control;

鉴于这对您来说并不明显,我认为您使用 Varnish 的策略是错误的决定。
