Bug #71243 [Ana->Csd]: session_start() returns true, even for invalid session ids
| From: | yohgaki@php.net | Date: | Tue, 12 Jan 2016 21:52:25 +0000 |
| Subject: | Bug #71243 [Ana->Csd]: session_start() returns true, even for invalid session ids | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-198613@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=71243&edit=1
ID: 71243
Updated by: yohgaki@php.net
Reported by: maggus dot staab at googlemail dot com
Summary: session_start() returns true, even for invalid
session ids
-Status: Analyzed
+Status: Closed
Type: Bug
Package: Session related
Operating System: Ubuntu12 lts
PHP Version: Irrelevant
Assigned To: yohgaki
Block user comment: N
Private report: N
Previous Comments:
------------------------------------------------------------------------
[2016-01-12 21:51:46] yohgaki@php.net
Bug #71122 is fixed and this bug is also fixed on PHP 7.0 and later.
------------------------------------------------------------------------
[2015-12-31 01:18:31] yohgaki@php.net
I have to kill broken save handler implementations also. i.e. BC
static void php_session_initialize(TSRMLS_D
**SNIP**
if (PS(mod)->s_read(&PS(mod_data), PS(id), &val, &vallen TSRMLS_CC) == FAILURE) {
/* Some broken save handler implementation returns FAILURE for non-existent session ID */
/* It's better to raise error for this, but disabled error for better compatibility */
/*
php_error_docref(NULL TSRMLS_CC, E_NOTICE, "Failed to read session data: %s (path: %s)",
PS(mod)->s_name, PS(save_path));
*/
}
------------------------------------------------------------------------
[2015-12-31 00:56:49] yohgaki@php.net
I have to change this function's signature
PHPAPI void php_session_start(TSRMLS_D)
Fix will be only for 7.1 and later.
------------------------------------------------------------------------
[2015-12-31 00:32:29] yohgaki@php.net
@maggus Thank you for the report.
The cause is different. The cause is
static void ps_files_open(ps_files *data, const char *key TSRMLS_DC)
is not returning status properly.
Many session internal functions were written w/o return values originally. It's time for
cleanup to fix these issues. Some of them will be only for PHP 7.1 as PHPAPI needs changes.
------------------------------------------------------------------------
[2015-12-30 10:14:18] maggus dot staab at googlemail dot com
Description:
------------
session_start() returns true, even if the configured session_id() is invalid.
This is similar to https://bugs.php.net/bug.php?id=65795 but I guess
the cause is different.
Test script:
---------------
https://3v4l.org/HXRoR
session_id('öäü');
var_dump(session_start());
Expected result:
----------------
Warning: The session id contains illegal characters, valid characters are a-z, A-Z, 0-9 and
'-,' in /in/HXRoR on line 4
bool(false)
Actual result:
--------------
Warning: The session id contains illegal characters, valid characters are a-z, A-Z, 0-9 and
'-,' in /in/HXRoR on line 4
bool(true)
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=71243&edit=1