Req #71289 [Ana]: JIT $_FILES initilization is required for multiple session.name to work

From: Date: Wed, 20 Jan 2016 16:19:42 +0000
Subject: Req #71289 [Ana]: JIT $_FILES initilization is required for multiple session.name to work
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-198801@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=71289&edit=1

 ID:                 71289
 User updated by:    pfenderd at bellsouth dot net
 Reported by:        pfenderd at bellsouth dot net
 Summary:            JIT $_FILES initilization is required for multiple
                     session.name to work
 Status:             Analyzed
 Type:               Feature/Change Request
 Package:            Session related
 Operating System:   any
 PHP Version:        irrelevant
 Block user comment: N
 Private report:     N

 New Comment:

Is there a difference in how sessions are handled using the API or the fast CGI on the server side? 
My testing has been on Windows 7 using IIS 7.5.  If there is a difference in the server type of
session handling, then this should be well documented so programmers can deal with it.

The problem has nothing to do with multiple files being uploaded, only a single file.


Previous Comments:
------------------------------------------------------------------------
[2016-01-07 05:14:39] yohgaki@php.net

Possible work around is to set session.name in .htaccess. "php_value" directive is
processed before uploaded file handling. If you use .htaccess (or like) to set different session
name, it should work. You'll need individual files, at least symlink, though.

------------------------------------------------------------------------
[2016-01-07 05:09:30] yohgaki@php.net

The reason why changing session name after module initialization does not work is the way RFC 1867
callback implemented.

Upload progress callback (php_rfc1867_callback) is registered when session module is initialized. It
is used when RFC 1867 upload is performed and handled in main/rfc1867.c. 

This means changing session name in user script is too late to make it work. I think it does not
work in older versions also, does it?

Possible fix would be delaying file upload handling and/or handle file upload manually. PHP handles
file uploading automatically now. Anyway, user cannot make use of
session_name('NEW_NAME')/ini_set('session.name', 'NEW_NAME') to use
multiple file upload progress handling. 

I checked the code briefly. Please correct me if I'm wrong.

------------------------------------------------------------------------
[2016-01-07 01:44:28] pfenderd at bellsouth dot net

More on the problem conditions:  To make the session_name() function work with
session.upload_progress, the session first needs to be started without using session_name() AND also
a file upload needs to be done.  Once the first file has been uploaded, then it is safe to use
session_name() and the progress feature will work properly.
Test using session_name(): http://upx.djpnet.dyndns.org/form1.php
Test without using session_name(): http://upx.djpnet.dyndns.org/form1.php?sn=0

------------------------------------------------------------------------
[2016-01-06 22:04:56] pfenderd at bellsouth dot net

The problem is a little bit more complicated than first thought. When a browser is first opened and
a session started using session_name() before session_start() the problem will continue to occur. 
However, if a session is opened without using session_name() just once, then thereafter the use of
session_name() will not cause a problem.  This is repeatable with IE 11, Firefox 43.0.4, Chrome
47.0.2526.106  and Opera 34.0.2036.31.
Test using session_name(): http://dayspeaknet.djpnet.dyndns.org/upload_sermons/upx/form1.php
Test without using session_name():
http://dayspeaknet.djpnet.dyndns.org/upload_sermons/upx/form1.php?sn=0

The only difference between these two test URLs is the use of session_name() or not.
Closing the browser and opening the browser again creates the problem situation.

------------------------------------------------------------------------
[2016-01-05 18:19:16] pfenderd at bellsouth dot net

When I mentioned session_progress, I was referring to the session.upload_progress feature.

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=71289


--
Edit this bug report at https://bugs.php.net/bug.php?id=71289&edit=1


Thread (7 messages)

« previous php.bugs (#198801) next »