Bug #38104 [Wfx->Csd]: session_start()/session_write_close() creates multiple session cookies headers
| From: | yohgaki@php.net | Date: | Tue, 11 Aug 2015 10:36:39 +0000 |
| Subject: | Bug #38104 [Wfx->Csd]: session_start()/session_write_close() creates multiple session cookies headers | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-195109@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=38104&edit=1
ID: 38104
Updated by: yohgaki@php.net
Reported by: m dot v dot veluw dot smscity at gmail dot com
Summary: session_start()/session_write_close() creates
multiple session cookies headers
-Status: Wont fix
+Status: Closed
Type: Bug
Package: Session related
Operating System: any
PHP Version: 5.1.4
Assigned To: yohgaki
Block user comment: N
Private report: N
New Comment:
Time goes by.
I fixed this already. If you have problem, please open new bug report.
Previous Comments:
------------------------------------------------------------------------
[2015-08-10 20:18:18] waldoc at latinmail dot com
A LOT of people is using session_start(); and session_write_close(); as a way to update $_SESSION
data and make it available for other scripts (usually called using AJAX)
The problem is session_start(); and his SEND HEADERS AGAIN Feature.
So the solution is simple:
Add a new function called session_write_open(); in order to be used with session_write_close();
Headers are only set by session_start(), and session_write_open() will resume that session without
sending headers again.
If that solution is too complicated, then add a new option to the session_start(); ie:
session_start(MUTE_HEADERS) that restore the session without send headers again.
I'm pretty sure that the second implementation is even more easy and fast to implement, because
if MUTE_HEADERS are set, then you got to skip the send header part of the function.
Hope this features will be present in the next release.
Best regards
------------------------------------------------------------------------
[2015-02-02 17:09:53] yohgaki@php.net
If only one header is sent, multiple sessions cannot be used. Therefore, it will not be fixed.
------------------------------------------------------------------------
[2014-09-10 10:29:27] yohgaki@php.net
I don't remember well, but I think I've dealt "multiple cookies" issue
partially. I might not for this case. I'll fix it sends multiple cookies, please let us know.
Unfortunately, PHP does not make sure that old session is not deleted. If old session was
authenticated before session regeneration, bad luck. (We could still say "it's users
fault", though)
To remove old session, it must be deleted asynchronous manner. However, few people against this
change and insist synchronous deletion which cannot be done. (i.e. Web server and client is _not_
synchronized, thus synchronous deletion can cause serious problem)
Anyway, please update PHP version if there is issue. If not, please close this again. Thank you.
------------------------------------------------------------------------
[2014-09-10 05:59:42] bgardner at noggin dot com dot au
The following highlights the bug
<?php
session_start();
$old_id = session_id();
session_regenerate_id();
$new_id = session_id();
session_write_close();
?>
<html>
<head>
<title>Session test</title>
</head>
<body>
<p>Old id : <?php print $old_id ?>
<p>New id : <?php print $new_id ?>
</body>
</html>
If you hit this page on a domain you have not previously visited, it will send two Set-Cookie
headers for the session id
This is a common scenario when logging in to prevent session fixation attacks
https://www.owasp.org/index.php/Session_fixation
This is not a problem if the user does
1. Login screen - display form controls to login
2. Submit credentials to login page - session regenerated
However, if they directly submit their credentials without first visiting the domain, then it does
occur
------------------------------------------------------------------------
[2013-05-29 02:47:34] jonathan at doubledotmedia dot com
I am encountering the same issue at the moment on a codebase I am working on; the
issue we are seeing is that we make many simultaneous AJAX requests, but they
block each other because only one can hold the session open at a time.
We are currently working around it by using multiple session_start() and
session_write_close() functions, but this is sending multiple (identical) Set-
Cookie headers to the client, which is incorrect.
Either session_start needs to not send duplicate headers, or we need a
session_reopen() function
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=38104
--
Edit this bug report at https://bugs.php.net/bug.php?id=38104&edit=1