Req #33786 [Asn->Csd]: $_SESSION not saving when an element's index contains pipe '|' character

From: Date: Sat, 04 Jan 2014 00:05:57 +0000
Subject: Req #33786 [Asn->Csd]: $_SESSION not saving when an element's index contains pipe '|' character
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-183577@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=33786&edit=1

 ID:                 33786
 Updated by:         yohgaki@php.net
 Reported by:        simon dot bettison at blueyonder dot co dot uk
 Summary:            $_SESSION not saving when an element's index
                     contains pipe '|' character
-Status:             Assigned
+Status:             Closed
 Type:               Feature/Change Request
 Package:            Session related
 Operating System:   Gentoo Linux
 PHP Version:        5.1.0b3
 Assigned To:        arpad
 Block user comment: N
 Private report:     N

 New Comment:

Use php_serialize save handler as previous comment.

php save handler has limitations that are originated from global session variable support.
Characters that cannot be variables names cannot be used as session var names with php save handler.


Previous Comments:
------------------------------------------------------------------------
[2014-01-03 23:30:34] charles dot capps at gmail dot com

http://us2.php.net/manual/en/session.configuration.php#ini.session.serialize-handler

As of 5.5.4, a new session serializer, "php_serialize", is available.  It uses the normal
plain vanilla PHP serialize function instead of the weird pipe-delimited nonsense, thus allowing
pipes to appear in session keys.

------------------------------------------------------------------------
[2013-07-09 15:01:37] boolie2051 at hotmail dot co dot uk

Can someone explain why| is not allowed in variable names but it is in array indexes.

------------------------------------------------------------------------
[2011-10-04 22:39:48] tkllingenberg at lastflood dot net

I assume this is because the serialized form of sessions (as for the PHP serialization handler)
contains the pipe character "|" as a separator between variable names.

The pipe example:

<?php
    $_SESSION['a|b'] = 'c';
    echo session_encode(); # '' - empty string
?>

I assume this, because other illegal variable names, like a variable starting with a number, _are_
possible, for example:

<?php
    $_SESSION['0a'] = '1a';
    echo session_encode(); # '0a|s:2:"1a";'
?>

If you change the session serialize-handler to "php_binary" (was: "php" in the
exmaples above), this might already work (returns values containing the data in both cases).

Tested against PHP 5.3.8.

------------------------------------------------------------------------
[2011-08-19 18:41:35] arpad@php.net

It's an artifact of register_globals/session_register, could be fixed now 
that they're gone and I wrote a patch to do so a couple of years ago but 
some issues emerged and I haven't got around to addressing them yet.

If you raise a feature request someone else may get to it sooner.

------------------------------------------------------------------------
[2011-08-19 15:09:42] lgandras at gmail dot com

May i ask why isn't the full session just serialized like a normal array?

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=33786


-- 
Edit this bug report at https://bugs.php.net/bug.php?id=33786&edit=1


Thread (9 messages)

« previous php.bugs (#183577) next »