#38353 [Opn->Bgs]: pipe char in index of SESSION variables should lead to error in session_encode

From: Date: Sun, 06 Aug 2006 13:49:03 +0000
Subject: #38353 [Opn->Bgs]: pipe char in index of SESSION variables should lead to error in session_encode
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-100424@lists.php.net to get a copy of this message
ID: 38353 Updated by: tony2001@php.net Reported By: wf at bitplan dot com -Status: Open +Status: Bogus Bug Type: Session related Operating System: All PHP Version: 5.1.4 New Comment: <?php session_start(); $_SESSION["v|ar"] = 1; var_dump(session_encode()); ?> bool(false) Previous Comments: ------------------------------------------------------------------------ [2006-08-06 06:15:18] wf at bitplan dot com Description: ------------ Please read carefully before rating i already had to reenter and rephrase since two existing bugreport where rated "bogus" which is the reason this bugreport is places in the first place. The rating is not o.k. Telling users "Read the fine manual" is not enough in this case because the cause is just a minor think the effect is devastating - that should not be. So please rate as "serious" to make sure the bug gets fixed. I'm sure it is a simple thing to add. The bugreports http://bugs.php.net/bug.php?id=33786 and http://bugs.php.net/bug.php?id=38346 have just the Status "bogus". That rating is not o.k. It's true that using pipe chars as part of an array index is not allowed - but the system should react better on this at least it should give a proper error message. With the current buggy behaviour of the system as an answer to the programming error session_encode will fail badly and a whole web - app will suffer (I've seen one report that someone lost his job due to sessions not being restored properly ...) A simple programming error that is hard to find and the whole system will be unusuable. PHP can do better than that and simply given an error message. Reproduce code: --------------- <?php for ($i=33;$i<255;$i++) { @session_destroy(); @session_start(); $_SESSION["validname"]="valid value"; $_varname="v".chr($i)."ar"; $_SESSION[$_varname]=$i; $data=session_encode(); if (strlen($data)==0) echo "when varname is ".$_varname. " session has ".count($_SESSION). " entries that are encoded with ".strlen($data)." bytes ". //" as '".$data. "'<br />"; } // for ?> Expected result: ---------------- A (fatal) error message on using | within the array index name for $_SESSION Actual result: -------------- when varname is v|ar session has 2 entries that are encoded with 0 bytes ' ------------------------------------------------------------------------ -- Edit this bug report at http://bugs.php.net/?id=38353&edit=1

« previous php.bugs (#100424) next »