Req #33786 [Asn->Csd]: $_SESSION not saving when an element's index contains pipe '|' character
Edit report at https://bugs.php.net/bug.php?id=33786&edit=1
ID: 33786
Updated by: yohgaki@php.net
Reported by: simon dot bettison at blueyonder dot co dot uk
Summary: $_SESSION not saving when an element's index
contains pipe '|' character
-Status: Assigned
+Status: Closed
Type: Feature/Change Request
Package: Session related
Operating System: Gentoo Linux
PHP Version: 5.1.0b3
Assigned To: arpad
Block user comment: N
Private report: N
New Comment:
Use php_serialize save handler as previous comment.
php save handler has limitations that are originated from global session variable support.
Characters that cannot be variables names cannot be used as session var names with php save handler.
Previous Comments:
------------------------------------------------------------------------
[2014-01-03 23:30:34] charles dot capps at gmail dot com
http://us2.php.net/manual/en/session.configuration.php#ini.session.serialize-handler
As of 5.5.4, a new session serializer, "php_serialize", is available. It uses the normal
plain vanilla PHP serialize function instead of the weird pipe-delimited nonsense, thus allowing
pipes to appear in session keys.
------------------------------------------------------------------------
[2013-07-09 15:01:37] boolie2051 at hotmail dot co dot uk
Can someone explain why| is not allowed in variable names but it is in array indexes.
------------------------------------------------------------------------
[2011-10-04 22:39:48] tkllingenberg at lastflood dot net
I assume this is because the serialized form of sessions (as for the PHP serialization handler)
contains the pipe character "|" as a separator between variable names.
The pipe example:
<?php
$_SESSION['a|b'] = 'c';
echo session_encode(); # '' - empty string
?>
I assume this, because other illegal variable names, like a variable starting with a number, _are_
possible, for example:
<?php
$_SESSION['0a'] = '1a';
echo session_encode(); # '0a|s:2:"1a";'
?>
If you change the session serialize-handler to "php_binary" (was: "php" in the
exmaples above), this might already work (returns values containing the data in both cases).
Tested against PHP 5.3.8.
------------------------------------------------------------------------
[2011-08-19 18:41:35] arpad@php.net
It's an artifact of register_globals/session_register, could be fixed now
that they're gone and I wrote a patch to do so a couple of years ago but
some issues emerged and I haven't got around to addressing them yet.
If you raise a feature request someone else may get to it sooner.
------------------------------------------------------------------------
[2011-08-19 15:09:42] lgandras at gmail dot com
May i ask why isn't the full session just serialized like a normal array?
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=33786
--
Edit this bug report at https://bugs.php.net/bug.php?id=33786&edit=1
Thread (9 messages)