Req->Bug #69073 [Opn->Nab]: SESSION is corrupt
| From: | requinix@php.net | Date: | Wed, 18 Feb 2015 19:28:31 +0000 |
| Subject: | Req->Bug #69073 [Opn->Nab]: SESSION is corrupt | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-190791@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=69073&edit=1
ID: 69073
Updated by: requinix@php.net
Reported by: martin dot schmitz at uni-bielefeld dot de
Summary: SESSION is corrupt
-Status: Open
+Status: Not a bug
-Type: Feature/Change Request
+Type: Bug
Package: Session related
Operating System: Linux / Mageia
PHP Version: 5.6Git-2015-02-18 (Git)
Block user comment: N
Private report: N
New Comment:
Sessions are generally persisted using cookies so this should be an obvious side-effect of disabling
them.
If this is a problem for your application, one common solution (besides telling your user to enable
cookies) is to put the session ID in the URL unless/until you've detected that cookies are
enabled. Which is risky. See also the session.use-trans-sid* INI setting where PHP will
automatically rewrite the URLs for you.
* http://php.net/manual/en/session.configuration.php#ini.session.use-trans-sid
Previous Comments:
------------------------------------------------------------------------
[2015-02-18 12:28:20] martin dot schmitz at uni-bielefeld dot de
Description:
------------
Session (SID) generates always an new id, when cookies are disabled (PHP Version 5.6.0)
Test script:
---------------
<?php
session_name('test');
session_start();
echo '<a href="?'.SID.'">test</a>'
?>
Expected result:
----------------
constant id, if no timeout kills session
Actual result:
--------------
always new id
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=69073&edit=1