Bug #71243 [Ana->Csd]: session_start() returns true, even for invalid session ids

From: Date: Tue, 12 Jan 2016 21:52:25 +0000
Subject: Bug #71243 [Ana->Csd]: session_start() returns true, even for invalid session ids
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-198613@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=71243&edit=1 ID: 71243 Updated by: yohgaki@php.net Reported by: maggus dot staab at googlemail dot com Summary: session_start() returns true, even for invalid session ids -Status: Analyzed +Status: Closed Type: Bug Package: Session related Operating System: Ubuntu12 lts PHP Version: Irrelevant Assigned To: yohgaki Block user comment: N Private report: N Previous Comments: ------------------------------------------------------------------------ [2016-01-12 21:51:46] yohgaki@php.net Bug #71122 is fixed and this bug is also fixed on PHP 7.0 and later. ------------------------------------------------------------------------ [2015-12-31 01:18:31] yohgaki@php.net I have to kill broken save handler implementations also. i.e. BC static void php_session_initialize(TSRMLS_D **SNIP** if (PS(mod)->s_read(&PS(mod_data), PS(id), &val, &vallen TSRMLS_CC) == FAILURE) { /* Some broken save handler implementation returns FAILURE for non-existent session ID */ /* It's better to raise error for this, but disabled error for better compatibility */ /* php_error_docref(NULL TSRMLS_CC, E_NOTICE, "Failed to read session data: %s (path: %s)", PS(mod)->s_name, PS(save_path)); */ } ------------------------------------------------------------------------ [2015-12-31 00:56:49] yohgaki@php.net I have to change this function's signature PHPAPI void php_session_start(TSRMLS_D) Fix will be only for 7.1 and later. ------------------------------------------------------------------------ [2015-12-31 00:32:29] yohgaki@php.net @maggus Thank you for the report. The cause is different. The cause is static void ps_files_open(ps_files *data, const char *key TSRMLS_DC) is not returning status properly. Many session internal functions were written w/o return values originally. It's time for cleanup to fix these issues. Some of them will be only for PHP 7.1 as PHPAPI needs changes. ------------------------------------------------------------------------ [2015-12-30 10:14:18] maggus dot staab at googlemail dot com Description: ------------ session_start() returns true, even if the configured session_id() is invalid. This is similar to https://bugs.php.net/bug.php?id=65795 but I guess the cause is different. Test script: --------------- https://3v4l.org/HXRoR session_id('öäü'); var_dump(session_start()); Expected result: ---------------- Warning: The session id contains illegal characters, valid characters are a-z, A-Z, 0-9 and '-,' in /in/HXRoR on line 4 bool(false) Actual result: -------------- Warning: The session id contains illegal characters, valid characters are a-z, A-Z, 0-9 and '-,' in /in/HXRoR on line 4 bool(true) ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=71243&edit=1

« previous php.bugs (#198613) next »