Bug #69073 [Nab]: SESSION is corrupt

From: Date: Thu, 19 Feb 2015 07:14:12 +0000
Subject: Bug #69073 [Nab]: SESSION is corrupt
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-190797@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=69073&edit=1 ID: 69073 Updated by: requinix@php.net Reported by: martin dot schmitz at uni-bielefeld dot de Summary: SESSION is corrupt Status: Not a bug Type: Bug Package: Session related Operating System: Linux / Mageia PHP Version: 5.6Git-2015-02-18 (Git) Block user comment: N Private report: N New Comment: >It's a bug, because session-handling does not work as it should. You should mention that to the people who design the HTTP standard. Make sure you CC the developers of browsers so that they know not to allow users to change configuration settings that may break your website. >It's a bug, because, if you set session_id($_REQUSET[PHPSESSID])) manually, it >works. What are your session.* INI settings? Specifically session.use_only_cookies. >If it is a risk to send the session per URL, it shouldn't be possible to do >this at all It's definitely risky. Which is why PHP doesn't use that behavior unless you go out of your way to enable it. >It's not right IMHO to force a user to set cookies You can say that all you want, it doesn't change the technical problem: without the URL or a cookie, PHP can't know which session to use for a request. Or maybe you have a suggestion for how to do that? Previous Comments: ------------------------------------------------------------------------ [2015-02-19 06:57:21] martin dot schmitz at uni-bielefeld dot de Sorry, but this answer is a bit "stupid": - It's a bug, because session-handling does not work as it should. - It's a bug, because, if you set session_id($_REQUSET[PHPSESSID])) manually, it works. - If it is a risk to send the session per URL, it shouldn't be possible to do this at all (any hacker knows, how to handle cookies, even it's described other way in the documentation). - It's not right IMHO to force a user to set cookies (I don't like them, and it worries me, if a page forces me to use them. Same for javascript.). My pages should work in every case. So if you want to see this effect: http://test.rtin.ws BTW. this error occured a few yeas ago (somewhere in PHP 4). Workaround: Set session_id() manually. But it's still a bug ------------------------------------------------------------------------ [2015-02-18 19:28:31] requinix@php.net Sessions are generally persisted using cookies so this should be an obvious side-effect of disabling them. If this is a problem for your application, one common solution (besides telling your user to enable cookies) is to put the session ID in the URL unless/until you've detected that cookies are enabled. Which is risky. See also the session.use-trans-sid* INI setting where PHP will automatically rewrite the URLs for you. * http://php.net/manual/en/session.configuration.php#ini.session.use-trans-sid ------------------------------------------------------------------------ [2015-02-18 12:28:20] martin dot schmitz at uni-bielefeld dot de Description: ------------ Session (SID) generates always an new id, when cookies are disabled (PHP Version 5.6.0) Test script: --------------- <?php session_name('test'); session_start(); echo '<a href="?'.SID.'">test</a>' ?> Expected result: ---------------- constant id, if no timeout kills session Actual result: -------------- always new id ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=69073&edit=1

« previous php.bugs (#190797) next »