Bug #71599 [Csd]: trans sid handling rework broke interaction with cookies
| From: | yohgaki@php.net | Date: | Wed, 06 Apr 2016 21:05:34 +0000 |
| Subject: | Bug #71599 [Csd]: trans sid handling rework broke interaction with cookies | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-200398@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=71599&edit=1
ID: 71599
Updated by: yohgaki@php.net
Reported by: phpbug at wisl dot de
Summary: trans sid handling rework broke interaction with
cookies
Status: Closed
Type: Bug
Package: Session related
Operating System: All
PHP Version: 7.0.3
Assigned To: yohgaki
Block user comment: N
Private report: N
New Comment:
Now I understand what is the issue. Do not report multiple issues at once next time.
Previous Comments:
------------------------------------------------------------------------
[2016-04-06 11:52:25] phpbug at wisl dot de
> - use_trans_sid=1, use_cookies=1 and use_only_cookies=0 do not add PHPSESSID params in URL and
> HTML form.
I wrote in the original report:
>Actual result:
>--------------
>Under PHP7 (tested with 7.0.2 and 7.0.3) it will:
> * no longer send a Set-Cookie Header, despite use_cookies=1 and >use_only_cookies=0
I can't reproduce this any longer. Possible I did not see this Header, because of previous
tries already set a cookie and I failed to clear it for this test.
But that was only a secondary concern, my main problem is:
> * will still rewrite the <a href> even if a cookies is already set
The problem is not, that PHP7 would fail to add the PHPSESSID parameter, but that it will still add
it, even when a cookie is set and so is not needed.
My usecase is as following:
1. Request: User has no Cookie, no Session
* session_start() will start a new Session
* I will call session_regenerate_id() to create a new, safe Session-ID
* Set-Cookie-Header will be send
* All URLs in this page will be rewritten to add PHPSESSID=...
2. Request:
Case A) User has Cookies allowed, the via Set-Cookie generated Cookie will be send back to the
server
* session_start() will resume the Session
* No Set-Cookie-Header, as there already was a Cookie available
* No changes to any URLs, because a Cookie was available
Case B) User did not allow Cookies
* session_start() will resume the Session, because all URLs from the first Request had PHPSESSID as
an normal URL parameter
* Set-Cookie-Header will be send again, but that is no problem, the user will just ignore it
* Because there was no Cookie, the URL-Rewriter for trans_sid will now also rewrite all URLs in this
second page. Because in this case of a Cookie-Forbidder these parameter are still needed.
This works fine with all versions of PHP5.
With PHP7 I see the following changes:
On 1. Request:
Wenn I call session_regenerate_id() after session_start() I now have 2 PHPSESSIDs in every URL. That
currently only looks ugly, but I'm not sure if this can result in any problems, if the wrong
one gets used.
That every URL gets an PHPSESSID added on this first request, even when a user has cookies allowed
is ugly and has already caused problems, but I 100% understand that this is the *correct and
intended behavior* of PHP. This is *not* what this bug report is about. (And this is the same in
PHP5 and PHP7)
On 2. Request:
Case B) is still working as intended under PHP7.
Case A) is the real problem: Under PHP7 the trans sid code will no longer silently turn off, when it
detects that a cookie is available. This is my problem: Now the 90+% of my vistitors that enable at
least session cookies will always get the ugliger URL version with the included PHPSESSID. Which
will then be used in bookmarks or shared including a stale session id.
These are the two things that I wanted to explain in https://bugs.php.net/bug.php?id=71599#1459868341
Under 1. the change removed the cookie check an now results in always adding PHPSESSID, even if not
needed.
Under 2. the change that caused multiple PHPSESSID to appear, and an explanation, why I think my use
case (first session_start(), then session_regenerate_id()) is a normal usage of the session API.
As you requested in:
[2016-04-06 00:17 UTC] yohgaki@php.net
> Please open new bug report for this and keep this one closed.
I have rereported this bug as Bug #71974 . Should we continue there?
If you want, I can also describe in more detail what I'm seeing with PHP5 / PHP7 with the small
testscripts bugtest.php and bugtest3.php from my previous comments, if these description are missing
something.
------------------------------------------------------------------------
[2016-04-06 10:57:49] yohgaki@php.net
OK. You've reported 2 issues on this report.
- Crash is caused because PHP 7 changed auto global behavior. Fixed.
- use_trans_sid=1, use_cookies=1 and use_only_cookies=0 do not add PHPSESSID params in URL and HTML
form.
I cannot reproduce 2nd issue. I verified that my browser stores/sends PHPSESSID cookie, displays
PHPSESSID on URL.
------------------------------------------------------------------------
[2016-04-06 10:22:52] phpbug at wisl dot de
[2016-04-06 00:17 UTC] yohgaki@php.net
>The issue mentioned on this bug report is crash bug that is caused by missing
>>zend_is_auto_global(). This is fixed.
I am the original reporter. And the original report was about the cookie problems. That's why
this bug has "trans sid handling rework broke interaction with cookies" as its subject.
I only mentioned the crash, because when trying to debug this issue I suddenly only got HTTP 500
from my local server, because now the php-cgi was crashing.
My Bug https://bugs.php.net/bug.php?id=71754 is
a duplicate of Bug #71683, because I did not really search when filing this bug, because the main
intention behind Bug #71754 was to get any attention, because this bug had been completely ignored
for nearly a complete month. OTOH #71754 demonstrated that this crash did not only happen in cli,
but also in the cgi version of PHP.
>Please open new bug report for this and keep this one closed. I think I >understand what is
>your problem, but please describe the issue in detail. >Thank you.
I will report a new bug to disentangle this...
[2016-04-06 00:33 UTC] yohgaki@php.net
>BTW, issue you're describing sounds like known issue (at least for me) for a >long time.
>To make sure it is known issue, please write short reproducible >code.
It is a clear regression between PHP5 and PHP7, as described at various comments. And a single Test
script, including "Expected result" and "Actual result" was provided in the
original bug report.
------------------------------------------------------------------------
[2016-04-06 00:33:22] yohgaki@php.net
BTW, issue you're describing sounds like known issue (at least for me) for a long time. To make
sure it is known issue, please write short reproducible code.
------------------------------------------------------------------------
[2016-04-06 00:17:47] yohgaki@php.net
The issue mentioned on this bug report is crash bug that is caused by missing zend_is_auto_global().
This is fixed.
Please open new bug report for this and keep this one closed. I think I understand what is your
problem, but please describe the issue in detail. Thank you.
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=71599
--
Edit this bug report at https://bugs.php.net/bug.php?id=71599&edit=1