#38353 [NEW]: pipe char in index of SESSION variables should lead to error in session_encode

From: Date: Sun, 06 Aug 2006 06:15:18 +0000
Subject: #38353 [NEW]: pipe char in index of SESSION variables should lead to error in session_encode
Groups: php.bugs 
Request: Send a blank email to php-bugs+get-100409@lists.php.net to get a copy of this message
From: wf at bitplan dot com Operating system: All PHP version: 5.1.4 PHP Bug Type: Session related Bug description: pipe char in index of SESSION variables should lead to error in session_encode Description: ------------ Please read carefully before rating i already had to reenter and rephrase since two existing bugreport where rated "bogus" which is the reason this bugreport is places in the first place. The rating is not o.k. Telling users "Read the fine manual" is not enough in this case because the cause is just a minor think the effect is devastating - that should not be. So please rate as "serious" to make sure the bug gets fixed. I'm sure it is a simple thing to add. The bugreports http://bugs.php.net/bug.php?id=33786 and http://bugs.php.net/bug.php?id=38346 have just the Status "bogus". That rating is not o.k. It's true that using pipe chars as part of an array index is not allowed - but the system should react better on this at least it should give a proper error message. With the current buggy behaviour of the system as an answer to the programming error session_encode will fail badly and a whole web - app will suffer (I've seen one report that someone lost his job due to sessions not being restored properly ...) A simple programming error that is hard to find and the whole system will be unusuable. PHP can do better than that and simply given an error message. Reproduce code: --------------- <?php for ($i=33;$i<255;$i++) { @session_destroy(); @session_start(); $_SESSION["validname"]="valid value"; $_varname="v".chr($i)."ar"; $_SESSION[$_varname]=$i; $data=session_encode(); if (strlen($data)==0) echo "when varname is ".$_varname. " session has ".count($_SESSION). " entries that are encoded with ".strlen($data)." bytes ". //" as '".$data. "'<br />"; } // for ?> Expected result: ---------------- A (fatal) error message on using | within the array index name for $_SESSION Actual result: -------------- when varname is v|ar session has 2 entries that are encoded with 0 bytes ' -- Edit bug report at http://bugs.php.net/?id=38353&edit=1 -- Try a CVS snapshot (PHP 4.4): http://bugs.php.net/fix.php?id=38353&r=trysnapshot44 Try a CVS snapshot (PHP 5.2): http://bugs.php.net/fix.php?id=38353&r=trysnapshot52 Try a CVS snapshot (PHP 6.0): http://bugs.php.net/fix.php?id=38353&r=trysnapshot60 Fixed in CVS: http://bugs.php.net/fix.php?id=38353&r=fixedcvs Fixed in release: http://bugs.php.net/fix.php?id=38353&r=alreadyfixed Need backtrace: http://bugs.php.net/fix.php?id=38353&r=needtrace Need Reproduce Script: http://bugs.php.net/fix.php?id=38353&r=needscript Try newer version: http://bugs.php.net/fix.php?id=38353&r=oldversion Not developer issue: http://bugs.php.net/fix.php?id=38353&r=support Expected behavior: http://bugs.php.net/fix.php?id=38353&r=notwrong Not enough info: http://bugs.php.net/fix.php?id=38353&r=notenoughinfo Submitted twice: http://bugs.php.net/fix.php?id=38353&r=submittedtwice register_globals: http://bugs.php.net/fix.php?id=38353&r=globals PHP 3 support discontinued: http://bugs.php.net/fix.php?id=38353&r=php3 Daylight Savings: http://bugs.php.net/fix.php?id=38353&r=dst IIS Stability: http://bugs.php.net/fix.php?id=38353&r=isapi Install GNU Sed: http://bugs.php.net/fix.php?id=38353&r=gnused Floating point limitations: http://bugs.php.net/fix.php?id=38353&r=float No Zend Extensions: http://bugs.php.net/fix.php?id=38353&r=nozend MySQL Configuration Error: http://bugs.php.net/fix.php?id=38353&r=mysqlcfg

« previous php.bugs (#100409) next »