Bug #68331 [Nab]: Session custom storage callable functions not being called

From: Date: Fri, 31 Oct 2014 15:07:24 +0000
Subject: Bug #68331 [Nab]: Session custom storage callable functions not being called
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-188384@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=68331&edit=1

 ID:                 68331
 User updated by:    mark at grooveshark dot com
 Reported by:        mark at grooveshark dot com
 Summary:            Session custom storage callable functions not being
                     called
 Status:             Not a bug
 Type:               Bug
 Package:            Session related
 Operating System:   All
 PHP Version:        5.6.2
 Block user comment: N
 Private report:     N

 New Comment:

Sorry about linking to the RFC incorrectly; however, what is the point of having an RFC if the
results are ignored by resolving a feature request bug with a finite feature from the RFC? The
feature request didn't even ask for what was implemented but rather just for a flag that a
session is dirty. The unfortunate part is that the RFC was created after the partial feature was
implemented (which for some reason is still assigned to PHP 4.2.1 in the bug tracker).

I feel like calling this not a bug is a mistake. The documentation does not state that storage
handlers won't be called in some cases. This results in custom session implementations having
to do the writing in close() with a bunch of convoluted logic to get the serialized session data
from read() or write(). The inability to have the timestamp updated via write() on a custom session
is a bug in my opinion. This would be fine if there were something like updateTimestamp as an
alternative.


Happy Halloween! Hope you have a good weekend.


Previous Comments:
------------------------------------------------------------------------
[2014-10-31 02:36:01] requinix@php.net

The state of the RFC and its code is a bit complicated. Suffice it to say that its changes are not
implemented yet.

The commit you found is regarding an old request which is separate from, though did play an
inspirational part in, the RFC.
  https://bugs.php.net/bug.php?id=17860
As such, the fact that the session handler (file or user or otherwise) is not called when there have
not been changes to the data is intentional.

Side note: the change was mentioned for 5.6.0.
  http://php.net/ChangeLog-5.php#5.6.0
(in the Session section as "Session write short circuit")

------------------------------------------------------------------------
[2014-10-31 00:43:52] mark at grooveshark dot com

Description:
------------
Call to write are not being triggered when setting up custom handlers for sessions using
session_set_save_handler if the underlying session data hasn't changed. It looks like this has
been done by design for regular session handling but was calls were suppose to happen for custom
session handling.

There wasn't really any documentation for this change in 5.6 but we found the commit and RFC
that caused this bug.

Here is the commit that caused the bug: https://github.com/php/php-src/commit/554021d21e1b2517313a377676260c188152c2eb#diff-52eb9eb7f9d5d9125fbb1337a6541c06R549

The RFC discussing the topic is here: https://wiki.php.net/rfc/session-lock-ini
It looks like read_only and lazy_write were accepted for this RFC.

Test script:
---------------
http://gobin.io/QfTs?php

Expected result:
----------------
Session's write custom handler should be called.

Actual result:
--------------
The custom write handler is not called.


------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=68331&edit=1


Thread (14 messages)

« previous php.bugs (#188384) next »