Bug #18855 [Com]: PHPSESSID, The Session Key is chagned in same page
| From: | otr214430 at gmail dot com | Date: | Sat, 09 Aug 2014 12:03:57 +0000 |
| Subject: | Bug #18855 [Com]: PHPSESSID, The Session Key is chagned in same page | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-187047@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=18855&edit=1
ID: 18855
Comment by: otr214430 at gmail dot com
Reported by: number3 at windogs dot com
Summary: PHPSESSID, The Session Key is chagned in same page
Status: No Feedback
Type: Bug
Package: Session related
Operating System: Linux 2.4.18
PHP Version: 4.2.2
Block user comment: N
Private report: N
New Comment:
Is Your VIRUS REMOVAL
Computer Sluggish or Plagued With a Virus? â If So you Need Online Tech Repairs
As a leader in online computer repair, Online Tech Repairs Inc has the experience to deliver
professional system optimization and virus removal.Headquartered in Great Neck, New York our
certified technicians have been providing online computer repair and virus removal for customers
around the world since 2004.
Our three step system is easy to use; and provides you a safe, unobtrusive, and cost effective
alternative to your computer service needs. By using state-of-the-art technology our computer
experts can diagnose, and repair your computer system through the internet, no matter where you are.
Our technician will guide you through the installation of Online Tech Repair Inc secure software.
This software allows your dedicated computer expert to see and operate your computer just as if he
was in the room with you. That means you don't have to unplug everything and bring it to our
shop, or have a stranger tramping through your home.
From our remote location the Online Tech Repairs.com expert can handle any computer issue you want
addressed, like:
⢠- System Optimization
⢠- How it works Software Installations or Upgrades
⢠- How it works Virus Removal
⢠- How it works Home Network Set-ups
Just to name a few.
If you are unsure of what the problem may be, that is okay. We can run a complete diagnostic on your
system and fix the problems we encounter. When we are done our software is removed; leaving you with
a safe, secure and properly functioning system. The whole process usually takes less than an hour.
You probably couldn't even get your computer to your local repair shop that fast!
Call us now for a FREE COMPUTER DIAGONISTIC using DISCOUNT CODE (otr214430@gmail.com) on
+1-914-613-3786 or chat with us on www.onlinetechrepairs.com.
Previous Comments:
------------------------------------------------------------------------
[2002-09-19 13:24:44] kalowsky@php.net
No feedback was provided. The bug is being suspended because
we assume that you are no longer experiencing the problem.
If this is not the case and you are able to provide the
information that was requested earlier, please do so and
change the status of the bug back to "Open". Thank you.
------------------------------------------------------------------------
[2002-08-13 21:50:24] kalowsky@php.net
I'm not sure I understand this bug completely, so bare with me. From what I gather, your code
writes a new userid based upon the userinfo->id, where the PHPSESSID is. From your example
though I don't see how this could be possible as the $PHPSESSID won't change during the
execution of the page.
But in any case, can you please provide a short sample script to reproduce this? It would help.
------------------------------------------------------------------------
[2002-08-11 08:30:54] number3 at windogs dot com
Hi,
i have used the php session with pgsql handler, for user authencation.
but I find that the php session key, PHPSESSID is changed same page. that sistuation is not always,
but a few time.
my debug code below.
--------------------------------------------
session_register("userinfo");
$q_update = "UPDATE session SET userid = '".$userinfo->id."' WHERE
sesskey = '".$PHPSESSID."'";
pg_exec($conn, $q_update);
--------------------------------------------
the register value "userinfo" is class var.
in debug result, the empty PHPSESSID value, not null value value is recorded.
and Session key is threr changed.
1. orginal sesskey
2. empty sesskey
3. new sesskey
That result in no login because sesskey is changed.
why that cause ?
addition, why be The PHPSESSID empty value ?
that is not normal. that situtaion result in session share.
1. user A -> login with sesskey1(sucess)
2. user B -> login with sesskey2(sucess)
3. user A -> logout and new sesskey in empty value
4. user B -> logout and new sesskey in empty value
5. so A and B share same sesskey.
After that sistuation,
6. user A login sucessful, and
user B load other page, that user B have user A's session value, so user A and B share session
with empty sesskey.
That is prevented from php session lib that empty value of sesskey no permitted.
thanks for advanced.
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=18855&edit=1