Bug #69952 [Asn->Csd]: Data integrity issues accessing superglobals by reference
| From: | bwoebi@php.net | Date: | Sun, 28 Jun 2015 14:31:21 +0000 |
| Subject: | Bug #69952 [Asn->Csd]: Data integrity issues accessing superglobals by reference | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-193962@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=69952&edit=1
ID: 69952
Updated by: bwoebi@php.net
Reported by: michael dot babker at gmail dot com
Summary: Data integrity issues accessing superglobals by
reference
-Status: Assigned
+Status: Closed
Type: Bug
Package: Session related
Operating System: N/A
PHP Version: 7.0.0alpha2
Assigned To: bwoebi
Block user comment: N
Private report: N
New Comment:
Automatic comment on behalf of bobwei9@hotmail.com
Revision: http://git.php.net/?p=php-src.git;a=commit;h=b477aa1fad6cac41ee6959921b229cb3dba79e6e
Log: Fix bug #69952 (Dereferencing issue in session_start())
Previous Comments:
------------------------------------------------------------------------
[2015-06-28 14:09:56] michael dot babker at gmail dot com
Ya, that was just me trying to reproduce what our internal code actually does as close as possible
(the isset is part of our input API and the is_null check in the session startup). Either way, glad
to see I haven't completely lost it :-)
------------------------------------------------------------------------
[2015-06-28 12:22:43] cmb@php.net
I can confirm the issue. The following test script is sufficient
to reproduce it:
<?php
$cookieData = &$_COOKIE;
session_start();
var_dump($_SESSION);
$_SESSION['foo'] = 'bar';
Apparently, the by-ref assignment causes a new session to be
created on each request.
@michael: The condition of the outermost if statement in your test
script is always FALSE, because a variable can't be isset() and
is_null().
------------------------------------------------------------------------
[2015-06-27 17:06:58] michael dot babker at gmail dot com
Description:
------------
Within Joomla, our input retrieval and setting API accesses the superglobals by reference. It
appears because of some of the engine refactoring, accessing the same data is not working the same
way. In the case of Joomla, this is most evident in our session boot sequence (extracted into the
test script below) where data validated in the $_COOKIE superglobal is no longer returned correctly.
Test script:
---------------
https://github.com/mbabker/session-test/blob/purephp/index.php
Expected result:
----------------
On each execution of the script, the session counter should increment by one.
Actual result:
--------------
On each execution of the script, the session counter's value is one.
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=69952&edit=1