Bug #71599 [ReO->Csd]: trans sid handling rework broke interaction with cookies
| From: | yohgaki@php.net | Date: | Fri, 11 Mar 2016 23:43:34 +0000 |
| Subject: | Bug #71599 [ReO->Csd]: trans sid handling rework broke interaction with cookies | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-199771@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=71599&edit=1
ID: 71599
Updated by: yohgaki@php.net
Reported by: phpbug at wisl dot de
Summary: trans sid handling rework broke interaction with
cookies
-Status: Re-Opened
+Status: Closed
Type: Bug
Package: Session related
Operating System: All
PHP Version: 7.0.3
Assigned To: yohgaki
Block user comment: N
Private report: N
New Comment:
Automatic comment on behalf of yohgaki
Revision: http://git.php.net/?p=php-src.git;a=commit;h=ca61f5954bf9e64072bfa31b4a7431e211a109e7
Log: Fixed Bug #71754 Regression in PHP7.0: trivial script segfaults php-cgi Fixed Bug #71683 Null
pointer dereference in zend_hash_str_find_bucket Fixed Bug #71599 trans sid handling rework broke
interaction with cookies
Previous Comments:
------------------------------------------------------------------------
[2016-03-11 09:07:42] cmb@php.net
> The logic wrt. the transparent session id when a cookie is
> available and that multiple calls to session_regenerate_id() add
> multiple PHPSESSID parameters is broken in PHP7 compared to
> PHP5.X [â¦]
The latter might be caused by
<https://github.com/php/php-src/commit/f248df900300c5b2201d4cf634d58d413399e2eb#diff-52eb9eb7f9d5d9125fbb1337a6541c06R1491>.
------------------------------------------------------------------------
[2016-03-11 08:08:02] phpbug at wisl dot de
This is not a duplicate of #71683.
The crash that I also noted might be a duplicate of #71683, but that got fixed as bug #71754.
The logic wrt. the transparent session id when a cookie is available and that multiple calls to
session_regenerate_id() add multiple PHPSESSID parameters is broken in PHP7 compared to PHP5.X and
this can't be fixed with the crash fix from #71683 or #71754.
Please reopen this bug.
------------------------------------------------------------------------
[2016-03-11 01:33:11] yohgaki@php.net
The cause is jit global change in PHP7.
Related to bug #71683
------------------------------------------------------------------------
[2016-03-10 18:12:43] cmb@php.net
Yasuo, could you please have a look at this issue?
------------------------------------------------------------------------
[2016-03-10 10:11:30] phpbug at wisl dot de
Crash has been fixed as Bug #71754: https://bugs.php.net/bug.php?id=71754
But the problem that the transparent session id rework is broken still persists.
session_regenerate_id() for example is also broken.
My application does a session_regenerate_id() when a new session is started to prevent session
fixation attacks. Because of that on the first request all URLs had two PHPSESSID parameter added.
The effect and that this is only broken in PHP7 can be seen with the following test script:
bugtest3.php:
<?php
ini_set("session.use_only_cookies","0");
ini_set("session.use_trans_sid","1");
session_start();
for($i=0;$i<$_REQUEST["count"];$i++) session_regenerate_id();
?>
<a href="bugtest3.php?count=0">0</a></br>
<a href="bugtest3.php?count=1">1</a></br>
<a href="bugtest3.php?count=2">2</a></br>
<a href="bugtest3.php?count=3">3</a></br>
Using the URL bugtest3.php?count=3 under PHP 5.5 without having a cookie set results in hrefs like
"bugtest3.php?count=3&PHPSESSID=f94bqpvtgksdiro232qolclut6". That is the correct and
expected behavior.
Under PHP 7.0.4 the URLs look like this:
"bugtest3.php?count=3&PHPSESSID=pgvvh2d39jpr4vnubnq2r2m800&PHPSESSID=umpctfqdp4q0av74l6mtflmqp3&PHPSESSID=a94c7n4694n2rrkqc2tlnlt1k3&PHPSESSID=ek4m6ikt29po9oh6045m1fpke2"
Each call to session_regenerate_id() seems to add another rewriter and an additional PHPSESSID
parameter.
Could somebody please look into this?
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=71599
--
Edit this bug report at https://bugs.php.net/bug.php?id=71599&edit=1