Bug #69073 [Nab]: SESSION is corrupt

From: Date: Thu, 19 Feb 2015 10:49:03 +0000
Subject: Bug #69073 [Nab]: SESSION is corrupt
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-190808@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=69073&edit=1 ID: 69073 Updated by: requinix@php.net Reported by: martin dot schmitz at uni-bielefeld dot de Summary: SESSION is corrupt Status: Not a bug Type: Bug Package: Session related Operating System: Linux / Mageia PHP Version: 5.6Git-2015-02-18 (Git) Block user comment: N Private report: N New Comment: SID includes the name. http://php.net/manual/en/session.constants.php Previous Comments: ------------------------------------------------------------------------ [2015-02-19 10:35:19] yohgaki@php.net BTW, trans sid has rather serious bug now. I strongly discourage using it... ------------------------------------------------------------------------ [2015-02-19 10:33:16] yohgaki@php.net session_name('test'); session_start(); echo '<a href="?'.SID.'">test</a> This code is wrong. session_name('test'); session_start(); echo '<a href="?test='.SID.'">test</a> is correct for trans_sid usage. ------------------------------------------------------------------------ [2015-02-19 10:22:47] requinix@php.net Make sure you're editing the right php.ini, and you're already restarting the server. Past experience has shown me that if the problem persists then there's some sort of server- or environment-specific situation to blame. Meanwhile, use_only_cookies can be set at runtime so you can at least test that. <?php ini_set("session.use_only_cookies", 0); session_name('test'); session_start(); echo '<a href="?'.SID.'">test</a>'; ?> ------------------------------------------------------------------------ [2015-02-19 09:54:04] martin dot schmitz at uni-bielefeld dot de I tried to set test it with session.use_only_cookies is "off" (canging the value in php.ini from "1" to "0", restart the server, but in php_info() it appears still as "on". However; I set session_id() manually to the value given by the $_REQUEST. ------------------------------------------------------------------------ [2015-02-19 09:27:59] requinix@php.net >What does HTTP standard has to do with PHP-session-handling? Everything. Why do you think the cookie mechanism exists in the first place? Because HTTP didn't provide a secure (relatively) method of maintaining state with a website - and arguably still doesn't. >session.use_only_cookies is "on" Great. Find out what that setting means and you should realize why you're having your disappearing SID problem (when the PHPSESSID is passed via the URL, that is). http://php.net/manual/en/session.configuration.php Then I asked for suggestions on how to keep sessions working when cookies are not available and the URL isn't an option, but I think you misunderstood my question. Either you need to adjust your session configuration, as I've hinted at, or you are stuck because there is nothing PHP can do. And neither of those qualify as bugs with PHP's behavior. I've said all that I can, which is more than this bug tracking system should be used for anyways. If you need someone to provide you with a different explanation of what's going on, try http://php.net/support.php ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=69073 -- Edit this bug report at https://bugs.php.net/bug.php?id=69073&edit=1

« previous php.bugs (#190808) next »