Bug #68063 [Opn->Csd]: Empty session IDs do still start sessions

From: Date: Tue, 03 Feb 2015 04:51:36 +0000
Subject: Bug #68063 [Opn->Csd]: Empty session IDs do still start sessions
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-190423@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=68063&edit=1 ID: 68063 Updated by: yohgaki@php.net Reported by: mail at thomasbachem dot com Summary: Empty session IDs do still start sessions -Status: Open +Status: Closed Type: Bug Package: Session related PHP Version: 5.5.17 Block user comment: N Private report: N New Comment: Automatic comment on behalf of yohgaki Revision: http://git.php.net/?p=php-src.git;a=commit;h=853ae39d6ea6a4d2ce95098744e481a1e8573ad8 Log: Fixed bug #68063 Empty session IDs do still start sessions Previous Comments: ------------------------------------------------------------------------ [2014-09-20 11:15:06] mail at thomasbachem dot com Description: ------------ If an empty session ID is given to PHP (e.g. a cookie with "PHPSESSID=; path=/" or simply by calling "session_id('')"), session_start() will throw an E_WARNING error from the default session handler ("session_start(): The session id is too long or contains illegal characters, valid characters are a-z, A-Z, 0-9 and '-,'") but still returns true and starts a session. Now session_id() returns '' (the manual states this only happens if there is no current session), but the session was still started, and custom session save handlers are given an empty session ID. If they don't handle that case, a session handler may then actually save session data for an empty session ID. Even the examples from the manual (http://php.net/manual/en/function.session-set-save-handler.php) don't check for an empty session ID. Test script: --------------- <?php // Could also be set with a cookie like "PHPSESSID=; path=/" session_id(''); // Will still start the session and return true var_dump(session_start()); // Returns an empty string var_dump(session_id()); Expected result: ---------------- I would expect session_start() to regenerate a session ID OR to fail, return false and not trigger any session save handlers. Actual result: -------------- Warning: session_start(): The session id is too long or contains illegal characters, valid characters are a-z, A-Z, 0-9 and '-,' in emptysession.php on line 5 boolean true string '' (length=0) Warning: Unknown: The session id is too long or contains illegal characters, valid characters are a-z, A-Z, 0-9 and '-,' in Unknown on line 0 Warning: Unknown: Failed to write session data (files). Please verify that the current setting of session.save_path is correct () in Unknown on line 0 ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=68063&edit=1

« previous php.bugs (#190423) next »