Bug #70013 [Asn]: Reference to $_SESSION is lost after a call to session_regenerate_id()

From: Date: Mon, 13 Jul 2015 16:09:40 +0000
Subject: Bug #70013 [Asn]: Reference to $_SESSION is lost after a call to session_regenerate_id()
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-194404@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=70013&edit=1

 ID:                 70013
 Updated by:         kalle@php.net
 Reported by:        jakub at zalas dot pl
 Summary:            Reference to $_SESSION is lost after a call to
                     session_regenerate_id()
 Status:             Assigned
 Type:               Bug
 Package:            Session related
 Operating System:   Debian
 PHP Version:        7.0Git-2015-07-07 (Git)
 Assigned To:        yohgaki
 Block user comment: N
 Private report:     N

 New Comment:

Yasuo,

Me and Anatol, talked it over and we both believe that the old behavior should be restored as to how
it was in PHP5. It creates a less WTF factor when upgrading too, even though the new behavior is
makes more sense.

So please go ahead and commit a fix to revert the behavior back before Beta 2


Previous Comments:
------------------------------------------------------------------------
[2015-07-13 02:21:26] yohgaki@php.net

So what should I do? Restore old behavior or not?

------------------------------------------------------------------------
[2015-07-11 20:44:59] ab@php.net

Hi,

I guess we should revert the change to PHP5 behavior. Please do a proof read of

https://wiki.php.net/rfc/session-lock-ini
http://grokbase.com/t/php/php-internals/142dbaan9h/vote-rfc-introduce-session-start-options-read-only-unsafe-lock-lazy-write-and-lazy-destroy

and also bug #65746. This behavior change is a subset of the mentioned RFC which had major concerns
and was declined. Until a proper solution is suggested and accepted, there is no reason to go for BC
breaks.

Thanks.

------------------------------------------------------------------------
[2015-07-11 06:39:55] mike@php.net

Autocorrection FTW.

Of course I meant application developer and s/codes/code/

------------------------------------------------------------------------
[2015-07-11 06:38:01] mike@php.net

It may seem more reasonable from an implementors point of view, because you're looking at the C
codes, but definitely does not seem reasonable for an appointment developer.

This breaks userland in an very unintuitive way.

------------------------------------------------------------------------
[2015-07-10 14:53:19] laruence@php.net

I'd like mark this as won't fix.. the new behaviors seems more reasonable

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=70013


--
Edit this bug report at https://bugs.php.net/bug.php?id=70013&edit=1


Thread (16 messages)

« previous php.bugs (#194404) next »