Edit report at https://bugs.php.net/bug.php?id=61470&edit=1
ID: 61470
User updated by: david at grudl dot com
Reported by: david at grudl dot com
Summary: session_regenerate_id() do not create session file
Status: Assigned
Type: Bug
Package: Session related
Operating System: ANY
PHP Version: 5.4.0
Assigned To: yohgaki
Block user comment: N
Private report: N
New Comment:
> there cannot be two concurrent requests for the same session?
They can be. session_regenerate_id() sends new cookie and next request is concurrent with the
current request.
Previous Comments:
------------------------------------------------------------------------
[2014-10-29 01:41:46] webmaster at tubo-world dot de
@yohgaki: I don't get it. Session file is created for locking on session_start for the given
id. But with session_regenerate_id you create a new, random session id. How would locking/creating a
session file make any difference when there cannot be two concurrent requests for the same session?
------------------------------------------------------------------------
[2014-10-27 00:14:41] yohgaki@php.net
Locking would not be useful most of the time. Shared session is rare in real apps, but such apps may
exist. Therefore, I would lock the file(data) as usual.
This bug is about new session ID file(data) isn't created when session_regenerate_id() is
called. It's inconsistent with automatic session ID generation. So I would like to fix this
issue in near future hopefully.
------------------------------------------------------------------------
[2014-10-26 23:41:45] webmaster at tubo-world dot de
There is no point in having session_regenerate_id create a file and lock.
It makes no sense at all since a parallel session_regenerate_id would create a different random ID
anyway.
All you have to make sure is, that you call session_write_close immediatly AFTER
session_regenerate_id as I also explained in #49462
This way, the data will be available on the next request. See also https://github.com/symfony/symfony/issues/7885
So I think the issue can be closed.
------------------------------------------------------------------------
[2014-09-08 13:12:30] craig at craigfrancis dot co dot uk
Related To: Bug #67736
------------------------------------------------------------------------
[2012-05-24 21:19:11] chris at netshake dot de
This Workaround works well for me.
// Session is already started
session_regenerate_id( true ); // delete old session
session_write_close(); // i'm not sure about that but it's required.
session_start(); // reinitialize session with newly created id from
'session_regenerate_id()'
I hope that future PHP-Versions will not make problems with this.
Greets Chris
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=61470
--
Edit this bug report at https://bugs.php.net/bug.php?id=61470&edit=1