Req #33786 [Com]: $_SESSION not saving when an element's index contains pipe '|' character

From: Date: Fri, 03 Jan 2014 23:30:35 +0000
Subject: Req #33786 [Com]: $_SESSION not saving when an element's index contains pipe '|' character
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-183575@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=33786&edit=1

 ID:                 33786
 Comment by:         charles dot capps at gmail dot com
 Reported by:        simon dot bettison at blueyonder dot co dot uk
 Summary:            $_SESSION not saving when an element's index
                     contains pipe '|' character
 Status:             Assigned
 Type:               Feature/Change Request
 Package:            Session related
 Operating System:   Gentoo Linux
 PHP Version:        5.1.0b3
 Assigned To:        arpad
 Block user comment: N
 Private report:     N

 New Comment:

http://us2.php.net/manual/en/session.configuration.php#ini.session.serialize-handler

As of 5.5.4, a new session serializer, "php_serialize", is available.  It uses the normal
plain vanilla PHP serialize function instead of the weird pipe-delimited nonsense, thus allowing
pipes to appear in session keys.


Previous Comments:
------------------------------------------------------------------------
[2013-07-09 15:01:37] boolie2051 at hotmail dot co dot uk

Can someone explain why| is not allowed in variable names but it is in array indexes.

------------------------------------------------------------------------
[2011-10-04 22:39:48] tkllingenberg at lastflood dot net

I assume this is because the serialized form of sessions (as for the PHP serialization handler)
contains the pipe character "|" as a separator between variable names.

The pipe example:

<?php
    $_SESSION['a|b'] = 'c';
    echo session_encode(); # '' - empty string
?>

I assume this, because other illegal variable names, like a variable starting with a number, _are_
possible, for example:

<?php
    $_SESSION['0a'] = '1a';
    echo session_encode(); # '0a|s:2:"1a";'
?>

If you change the session serialize-handler to "php_binary" (was: "php" in the
exmaples above), this might already work (returns values containing the data in both cases).

Tested against PHP 5.3.8.

------------------------------------------------------------------------
[2011-08-19 18:41:35] arpad@php.net

It's an artifact of register_globals/session_register, could be fixed now 
that they're gone and I wrote a patch to do so a couple of years ago but 
some issues emerged and I haven't got around to addressing them yet.

If you raise a feature request someone else may get to it sooner.

------------------------------------------------------------------------
[2011-08-19 15:09:42] lgandras at gmail dot com

May i ask why isn't the full session just serialized like a normal array?

------------------------------------------------------------------------
[2005-07-20 13:37:34] sniper@php.net

| is not allowed in variable names. (yes, I know you can use it in array indexes, but $_SESSION is
special in many ways)


------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=33786


-- 
Edit this bug report at https://bugs.php.net/bug.php?id=33786&edit=1


Thread (9 messages)

« previous php.bugs (#183575) next »