#18855 [Opn->Fbk]: PHPSESSID, The Session Key is chagned in same page

From: Date: Wed, 14 Aug 2002 01:50:24 +0000
Subject: #18855 [Opn->Fbk]: PHPSESSID, The Session Key is chagned in same page
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-16670@lists.php.net to get a copy of this message
ID: 18855 Updated by: kalowsky@php.net Reported By: number3@windogs.com -Status: Open +Status: Feedback Bug Type: Session related Operating System: Linux 2.4.18 PHP Version: 4.2.2 New Comment: I'm not sure I understand this bug completely, so bare with me. From what I gather, your code writes a new userid based upon the userinfo->id, where the PHPSESSID is. From your example though I don't see how this could be possible as the $PHPSESSID won't change during the execution of the page. But in any case, can you please provide a short sample script to reproduce this? It would help. Previous Comments: ------------------------------------------------------------------------ [2002-08-11 08:30:54] number3@windogs.com Hi, i have used the php session with pgsql handler, for user authencation. but I find that the php session key, PHPSESSID is changed same page. that sistuation is not always, but a few time. my debug code below. -------------------------------------------- session_register("userinfo"); $q_update = "UPDATE session SET userid = '".$userinfo->id."' WHERE sesskey = '".$PHPSESSID."'"; pg_exec($conn, $q_update); -------------------------------------------- the register value "userinfo" is class var. in debug result, the empty PHPSESSID value, not null value value is recorded. and Session key is threr changed. 1. orginal sesskey 2. empty sesskey 3. new sesskey That result in no login because sesskey is changed. why that cause ? addition, why be The PHPSESSID empty value ? that is not normal. that situtaion result in session share. 1. user A -> login with sesskey1(sucess) 2. user B -> login with sesskey2(sucess) 3. user A -> logout and new sesskey in empty value 4. user B -> logout and new sesskey in empty value 5. so A and B share same sesskey. After that sistuation, 6. user A login sucessful, and user B load other page, that user B have user A's session value, so user A and B share session with empty sesskey. That is prevented from php session lib that empty value of sesskey no permitted. thanks for advanced. ------------------------------------------------------------------------ -- Edit this bug report at http://bugs.php.net/?id=18855&edit=1

« previous php.bugs (#16670) next »