Bug #70013 [Opn]: Reference to $_SESSION is lost after a call to session_regenerate_id()
| From: | ab@php.net | Date: | Sat, 11 Jul 2015 20:45:01 +0000 |
| Subject: | Bug #70013 [Opn]: Reference to $_SESSION is lost after a call to session_regenerate_id() | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-194336@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=70013&edit=1
ID: 70013
Updated by: ab@php.net
Reported by: jakub at zalas dot pl
Summary: Reference to $_SESSION is lost after a call to
session_regenerate_id()
Status: Open
Type: Bug
Package: Session related
Operating System: Debian
PHP Version: 7.0Git-2015-07-07 (Git)
Block user comment: N
Private report: N
New Comment:
Hi,
I guess we should revert the change to PHP5 behavior. Please do a proof read of
https://wiki.php.net/rfc/session-lock-ini
http://grokbase.com/t/php/php-internals/142dbaan9h/vote-rfc-introduce-session-start-options-read-only-unsafe-lock-lazy-write-and-lazy-destroy
and also bug #65746. This behavior change is a subset of the mentioned RFC which had major concerns
and was declined. Until a proper solution is suggested and accepted, there is no reason to go for BC
breaks.
Thanks.
Previous Comments:
------------------------------------------------------------------------
[2015-07-11 06:39:55] mike@php.net
Autocorrection FTW.
Of course I meant application developer and s/codes/code/
------------------------------------------------------------------------
[2015-07-11 06:38:01] mike@php.net
It may seem more reasonable from an implementors point of view, because you're looking at the C
codes, but definitely does not seem reasonable for an appointment developer.
This breaks userland in an very unintuitive way.
------------------------------------------------------------------------
[2015-07-10 14:53:19] laruence@php.net
I'd like mark this as won't fix.. the new behaviors seems more reasonable
------------------------------------------------------------------------
[2015-07-10 09:06:02] mike@php.net
+1, "deleting the session", if ever should mean on the backend under the old key; the data
will stay the same and a reference to it should be kept intact.
------------------------------------------------------------------------
[2015-07-09 09:16:17] tyrael@php.net
Bob: first of all, deleting the old session won't happen by default, so your definition is a
bit misleading, and also, from the "new" session will hold the same data only under a
different session id, so I think not many people would expect that the $_SESSION superglobal will be
recreated hence losing the reference.
if you add this to the fact that this is an undocumented behavior change I think we should consider
this a bug and fix it.
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=70013
--
Edit this bug report at https://bugs.php.net/bug.php?id=70013&edit=1