Bug #66827 [Opn->Asn]: session_start generates PHP Notice if session cookie contains array
| From: | yohgaki@php.net | Date: | Sun, 06 Jul 2014 02:27:38 +0000 |
| Subject: | Bug #66827 [Opn->Asn]: session_start generates PHP Notice if session cookie contains array | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-186487@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=66827&edit=1
ID: 66827
Updated by: yohgaki@php.net
Reported by: spam at krol dot me
Summary: session_start generates PHP Notice if session cookie
contains array
-Status: Open
+Status: Assigned
Type: Bug
Package: Session related
Operating System: osx
PHP Version: 5.5.9
-Assigned To:
+Assigned To: yohgaki
Block user comment: N
Private report: N
Previous Comments:
------------------------------------------------------------------------
[2014-03-06 13:04:15] patryk dot kozlowski at toxic-software dot pl
Many developers consider sessions as internal PHP mechanism and don't bother to check for
session id malformation. If you want to keep this 'call session_start & play'
standard, this bug definitely need a fix (as spam mentioned: is_string will do the job).
For now you can trigger PHP_Notice error on many PHP websites (including ZF based) by executing
one-line JavaScript code.
------------------------------------------------------------------------
[2014-03-06 12:36:17] narf at devilix dot net
Hmm, I guess you do have a point in that, although I'm not sure how $_COOKIE itself is
populated.
------------------------------------------------------------------------
[2014-03-06 12:28:21] spam at krol dot me
If malformed cookie can cause application error i would consider this as a bug.
Maybe at least is_string check before unserialize?
If not I think this can be closed.
------------------------------------------------------------------------
[2014-03-06 12:17:44] narf at devilix dot net
That's completely natural, since the cookie value is unserialized by session_start() and you
can't unserialize an array(). I wouldn't consider it a bug.
------------------------------------------------------------------------
[2014-03-05 15:07:35] spam at krol dot me
Description:
------------
If session cookie contains array instead of session_id string, on session_start() call PHP Notice is
generated.
Test script:
---------------
<?php
$sessionName = "PHPSESSID";
session_name($sessionName);
$_COOKIE[$sessionName]['key'] = 'value';
session_start();
Expected result:
----------------
false
Actual result:
--------------
PHP Notice: Array to string conversion in /private/tmp/session-fail.php on line 8
PHP Stack trace:
PHP 1. {main}() /private/tmp/session-fail.php:0
PHP 2. session_start() /private/tmp/session-fail.php:8
true
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=66827&edit=1