Bug #66469 [ReO->Csd]: PHP creates two session ids when using strict mode

From: Date: Wed, 22 Jan 2014 04:50:47 +0000
Subject: Bug #66469 [ReO->Csd]: PHP creates two session ids when using strict mode
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-183946@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=66469&edit=1

 ID:                 66469
 Updated by:         yohgaki@php.net
 Reported by:        oz at zend dot com
 Summary:            PHP creates two session ids when using strict mode
-Status:             Re-Opened
+Status:             Closed
 Type:               Bug
 Package:            Session related
 Operating System:   All
 PHP Version:        5.5.8
 Assigned To:        yohgaki
 Block user comment: N
 Private report:     N

 New Comment:

Automatic comment on behalf of yohgaki
Revision: http://git.php.net/?p=php-src.git;a=commit;h=a27e51fd4e9121f962821d0f7bd1960fce0a0fd5
Log: Re-fixed bug #66469


Previous Comments:
------------------------------------------------------------------------
[2014-01-21 09:18:16] yohgaki@php.net

Looks like I have to modify code so that session module calls 

 php_session_reset_id(TSRMLS_C);

only once. Reopened.

------------------------------------------------------------------------
[2014-01-17 03:40:02] yohgaki@php.net

BTW, 5.6 part of diff is committed last year, not this year.

------------------------------------------------------------------------
[2014-01-17 03:37:55] yohgaki@php.net

Thank you, kaplan.
The commit is the fix. I don't know why the link shows patch applicable only to 5.6 branch,
though. (It's not in 5.5 branch)

Closing.

------------------------------------------------------------------------
[2014-01-15 14:33:44] kaplan@php.net

This commit might be relevant for this bug: http://git.php.net/?p=php-src.git;a=commitdiff;h=167eaedcbdb494c87c4f83d2897a9fdb614e7062

------------------------------------------------------------------------
[2014-01-12 08:28:12] oz at zend dot com

Description:
------------
When you enable the strict mode and then you execute session_start() without supplying a PHPSESSID
(using php-cgi, cli, or ApacheBench for example), PHP creates two session ids and returns two
SetCookie headers with both session ids.

I believe the second session id can be avoided since PHP knows it just created the session id for
the first time.

Test script:
---------------
<?php
ini_set("session.use_strict_mode", "1");
ini_set("session.save_handler", "files");
session_start();
?>


Expected result:
----------------
"
Set-Cookie: PHPSESSID=k6brqpp9rnh2ajo2tch4l68t84; path=/
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Content-type: text/html
"


Actual result:
--------------
"
Set-Cookie: PHPSESSID=k1hn6r22om8kiq60nq72hhsa52; path=/
Set-Cookie: PHPSESSID=k6brqpp9rnh2ajo2tch4l68t84; path=/
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Content-type: text/html
"



------------------------------------------------------------------------



-- 
Edit this bug report at https://bugs.php.net/bug.php?id=66469&edit=1


Thread (7 messages)

« previous php.bugs (#183946) next »