Req #62743 [Fbk->NoF]: Empty, but set session cookies cause warning and cause sessions to not save
| From: | php-bugs at lists dot php dot net | Date: | Tue, 15 Oct 2013 11:54:35 +0000 |
| Subject: | Req #62743 [Fbk->NoF]: Empty, but set session cookies cause warning and cause sessions to not save | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-182213@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=62743&edit=1
ID: 62743
Updated by: php-bugs@lists.php.net
Reported by: brianlmoon@php.net
Summary: Empty, but set session cookies cause warning and cause
sessions to not save
-Status: Feedback
+Status: No Feedback
Type: Feature/Change Request
Package: Session related
Operating System: Linux
PHP Version: 5.3.15
Private report: N
New Comment:
No feedback was provided. The bug is being suspended because
we assume that you are no longer experiencing the problem.
If this is not the case and you are able to provide the
information that was requested earlier, please do so and
change the status of the bug back to "Re-Opened". Thank you.
Previous Comments:
------------------------------------------------------------------------
[2013-06-27 09:00:51] yohgaki@php.net
If session cookie is empty string, cookie should be deleted.
Do you mean string looks empty? i.e. ' ' for instance.
If multiple cookie for the same name is set (i.e. set path and/or domain for
cookie), already existing cookie may not be able to be
overwritten by new cookie.
Your case sounds like later case. If so, it's the cookie spec and we cannot do
much and please close this bug report.
We can try to delete all the possible pattern of path and domain for session
cookie, but I think it's users task.
------------------------------------------------------------------------
[2012-08-03 17:40:47] brianlmoon@php.net
Description:
------------
If a session cookie is not set, a new session id will be created and all works fine. However, if for
some reason the session cookie is set, but an empty string, session_start() throws a warning and
custom session handlers are called with an empty session id. In addition, no session cookies are
set.
Test script:
---------------
The test script involves setting empty cookies and such. This is the user land workaround I am using
for now.
if(isset($_COOKIE[ini_get("session.name")]) &&
empty($_COOKIE[ini_get("session.name")])){
// The cookie is empty. This is bad.
unset($_COOKIE[ini_get("session.name")]);
}
session_start();
Expected result:
----------------
An empty session cookie should be treated the same as an unset session cookie.
Actual result:
--------------
Empty session cookies are treated as session ids, but warned and cause sessions to not be saved.
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=62743&edit=1