Bug #71162 [Asn->Ana]: updateTimestamp is called always when session is empty

From: Date: Fri, 15 Jan 2016 21:47:28 +0000
Subject: Bug #71162 [Asn->Ana]: updateTimestamp is called always when session is empty
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-198695@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=71162&edit=1

 ID:                 71162
 Updated by:         yohgaki@php.net
 Reported by:        e2c2be7ed0f2f336 at gmail dot com
 Summary:            updateTimestamp is called always when session is
                     empty
-Status:             Assigned
+Status:             Analyzed
 Type:               Bug
 Package:            Session related
 PHP Version:        7.0Git-2015-12-18 (snap)
 Assigned To:        yohgaki
 Block user comment: N
 Private report:     N

 New Comment:

I cannot change "php" serialize handler's behavior, but you may use
"php_serialize" handler. 

session.serialize_handler=php_serialize

It saves 

a:0:{}

for empty $_SESSION and timestamp would work.

So this bug could be considered as feature request for setting "php_serialize" as the
default serialize handler. "php_serialize" does not have restrictions for session
variables names also. It should be the default.


Previous Comments:
------------------------------------------------------------------------
[2015-12-20 02:42:26] yohgaki@php.net

Added phpt for this.

http://git.php.net/?p=php-src.git;a=commitdiff;h=0cf7143441c74091fb7bb2979513e6b937e4866c

------------------------------------------------------------------------
[2015-12-20 00:10:38] yohgaki@php.net

Current session module is designed to write empty session always. I don't think I can change to
update time stamp for empty session. (Session module cannot know empty session is new one or not,
currently. Session module may detect it, though. This requires yet another state management which is
rather complicated already.)

Other than this, I noticed session_set_save_handler() changed the way not to accept
SessionIdHandlerInterface nor SessionUpdateTimestampHandlerInterface by someone else.

Therefore, there is no way to use object version of save handler implements
SessionIdHandlerInterface or SessionUpdateTimestampHandlerInterface. 

Other parts of object based user save handler implementation needs clean up also. Assign this bug to
me for session module clean up in the future.

------------------------------------------------------------------------
[2015-12-18 22:54:36] e2c2be7ed0f2f336 at gmail dot com

Description:
------------
A session which remains empty always invoke the write callback instead of updateTimestamp of the
session handler.

Not really a bug but behavior would be more consistent.

Test script:
---------------
https://gist.github.com/julp/4bc6acac8ef4ca51e750

Expected result:
----------------
updateTimestamp

Actual result:
--------------
write


------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=71162&edit=1


Thread (5 messages)

« previous php.bugs (#198695) next »