Bug #70520 [Ver]: session_regenerate_id() "Failed to create session ID" with custom SessionHandler
| From: | yohgaki@php.net | Date: | Fri, 18 Sep 2015 08:58:40 +0000 |
| Subject: | Bug #70520 [Ver]: session_regenerate_id() "Failed to create session ID" with custom SessionHandler | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-196068@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=70520&edit=1
ID: 70520
Updated by: yohgaki@php.net
Reported by: hpdl at oscommerce dot com
Summary: session_regenerate_id() "Failed to create session
ID" with custom SessionHandler
Status: Verified
Type: Bug
Package: Session related
Operating System: Win10
PHP Version: 7.0.0RC3
Assigned To: yohgaki
Block user comment: N
Private report: N
New Comment:
It seems Windows only, doesn't it?
I tried the save handler with php-7.0.0RC3 tag and PHP-7.0 branch on my linux box and it works.
Is your session.save_path a local filesystem? i.e. It's not Windows share or like. I know some
users are having problem with shared file systems.
Previous Comments:
------------------------------------------------------------------------
[2015-09-18 00:06:49] requinix@php.net
Okay, I see it. So rather it's a general failure when overriding SessionHandler::write(), not
about the save path.
(Note that the first echo needs to be commented out as it creates output which will interfere.)
Tentatively assigning to @yohgaki as he did some work with session_regenerate_id() before the RC3
release.
------------------------------------------------------------------------
[2015-09-17 23:11:47] hpdl at oscommerce dot com
Sorry, the problem seems to be with custom session handlers.
Below is a snippet that reproduces the problem. The handler used below is taken from the PHP
documentation:
http://php.net/manual/en/class.sessionhandler.php
<?php
error_reporting(E_ALL | E_STRICT);
ini_set('display_errors', true);
class EncryptedSessionHandler extends SessionHandler
{
private $key;
public function __construct($key)
{
$this->key = $key;
}
public function read($id)
{
$data = parent::read($id);
return @mcrypt_decrypt(MCRYPT_3DES, $this->key, $data, MCRYPT_MODE_ECB);
}
public function write($id, $data)
{
$data = @mcrypt_encrypt(MCRYPT_3DES, $this->key, $data, MCRYPT_MODE_ECB);
return parent::write($id, $data);
}
}
ini_set('session.save_handler', 'files');
$handler = new EncryptedSessionHandler('mykey');
session_set_save_handler($handler, true);
session_start();
echo session_id() . '<br>';
session_regenerate_id(true);
echo session_id();
------------------------------------------------------------------------
[2015-09-17 19:56:25] requinix@php.net
Seems to be working for me.
<?php
session_save_path(".");
session_start();
$sid1 = session_id();
$exists1 = file_exists("./sess_{$sid1}");
session_regenerate_id();
$sid2 = session_id();
$exists2 = file_exists("./sess_{$sid2}");
var_dump($exists1); // true
var_dump($sid1 != $sid2); // true
var_dump($exists2); // true
?>
What's your test script? Can you dump session_save_path() before the session_regenerate_id() to
make sure it's set appropriately?
------------------------------------------------------------------------
[2015-09-17 14:53:22] hpdl at oscommerce dot com
Description:
------------
session_regenerate_id() ignores a defined session path (via session_save_path()) and uses the
windows\temp directory instead.
Did not occur in earlier RC releases.
Test script:
---------------
session_regenerate_id();
Expected result:
----------------
true
Actual result:
--------------
session_regenerate_id(): Failed to create session ID: user (path: C:\WINDOWS\Temp\) in
C:\Users\blahblah\blah.php
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=70520&edit=1