Bug #70013 [Com]: Reference to $_SESSION is lost after a call to session_regenerate_id()
| From: | stloyd at o2 dot pl | Date: | Wed, 08 Jul 2015 07:06:53 +0000 |
| Subject: | Bug #70013 [Com]: Reference to $_SESSION is lost after a call to session_regenerate_id() | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-194198@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=70013&edit=1
ID: 70013
Comment by: stloyd at o2 dot pl
Reported by: jakub at zalas dot pl
Summary: Reference to $_SESSION is lost after a call to
session_regenerate_id()
Status: Open
Type: Bug
Package: Session related
Operating System: Debian
PHP Version: 7.0Git-2015-07-07 (Git)
Block user comment: N
Private report: N
New Comment:
This is BC break that can be easily reproduced: http://3v4l.org/PRhdj
Previous Comments:
------------------------------------------------------------------------
[2015-07-07 23:44:03] jakub at zalas dot pl
Description:
------------
If a reference to $_SESSION is assigned to another variable, it is lost after a call to
session_regenerate_id(). It is not lost in previous PHP versions, and Symfony's HttpFoundation
actually relies on this behaviour.
php -v
PHP 7.0.0-dev (cli) (built: Jul 7 2015 22:52:27) (DEBUG)
Copyright (c) 1997-2015 The PHP Group
Zend Engine v3.0.0-dev, Copyright (c) 1998-2015 Zend Technologies
with Zend OPcache v7.0.6-dev, Copyright (c) 1999-2015, by Zend Technologies
Test script:
---------------
session_start();
$session = &$_SESSION;
$session['test'] = 1;
session_regenerate_id(false);
$session['test'] = 2;
// dumps false, should be true
var_dump($session['test'] === $_SESSION['test']);
Expected result:
----------------
bool(true)
Actual result:
--------------
bool(false)
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=70013&edit=1