Bug #71974 [NEW]: Regression PHP5->7: trans sid will always be send,even if cookies are available
| From: | phpbug at wisl dot de | Date: | Wed, 06 Apr 2016 10:28:56 +0000 |
| Subject: | Bug #71974 [NEW]: Regression PHP5->7: trans sid will always be send,even if cookies are available | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-200408@lists.php.net to get a copy of this message | ||
From: phpbug at wisl dot de
Operating system: All
PHP version: 7.0.5
Package: Session related
Bug Type: Bug
Bug description:Regression PHP5->7: trans sid will always be send,even if cookies are available
Description:
------------
I am using session.use_trans_sid=1 as a transparent fallback for users
who have cookies disabled. By setting both use_trans_sid and use_cookies
until PHP7 the cookie users would silently be upgraded to using cookies,
while users without cookies could still use the session related function
due to PHPSESSID that was written automatically into the html.
Cause seems to be this commit:
https://github.com/php/php-src/commit/f248df900300c5b2201d4cf634d58d413399e2eb
"Cleanup trans sid code. Behavior is unchanged."
But the behavior is changed, because the new macro APPLY_TRANS_SID only
looks for the ini settings use_trans_sid and use_only_cookies, but the
code wrt. cookies like lines 540+541 was removed.
Test script:
---------------
<?php
ini_set("session.use_cookies","1");
ini_set("session.use_only_cookies","0");
ini_set("session.use_trans_sid","1");
session_start();
?>
<a href="bugtest.php">Follow Me</a>
Expected result:
----------------
On first call to the supplied test script (wenn saved as bugtest.php)
the use_trans_sid feature will insert an additional parameter PHPSESSID
into the <a href>, but because of use_cookies the script will also send
an Set-Cookie-Header.
After clicking the link, the same page will reopen again. But if cookies
are allowed in the browser, the <a href> will now no longer contain a
PHPSESSID parameter.
After clicking the link, the <a href> should only still contain a
PHPSESSID parameter, if there was no cookie set.
This behavior works as expected as of PHP 5.6.18.
Actual result:
--------------
Under PHP7 (tested with 7.0.2, 7.0.3, 7.0.4, 7.0.5) it will:
* no longer send a Set-Cookie Header, despite use_cookies=1 and
use_only_cookies=0
* will still rewrite the <a href> even if a cookies is already set
--
Edit bug report at https://bugs.php.net/bug.php?id=71974&edit=1
--
Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=71974&r=trysnapshot54
Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=71974&r=trysnapshot55
Try a snapshot (trunk): https://bugs.php.net/fix.php?id=71974&r=trysnapshottrunk
Fixed in SVN: https://bugs.php.net/fix.php?id=71974&r=fixed
Fixed in release: https://bugs.php.net/fix.php?id=71974&r=alreadyfixed
Need backtrace: https://bugs.php.net/fix.php?id=71974&r=needtrace
Need Reproduce Script: https://bugs.php.net/fix.php?id=71974&r=needscript
Try newer version: https://bugs.php.net/fix.php?id=71974&r=oldversion
Not developer issue: https://bugs.php.net/fix.php?id=71974&r=support
Expected behavior: https://bugs.php.net/fix.php?id=71974&r=notwrong
Not enough info: https://bugs.php.net/fix.php?id=71974&r=notenoughinfo
Submitted twice: https://bugs.php.net/fix.php?id=71974&r=submittedtwice
register_globals: https://bugs.php.net/fix.php?id=71974&r=globals
PHP 4 support discontinued: https://bugs.php.net/fix.php?id=71974&r=php4
Daylight Savings: https://bugs.php.net/fix.php?id=71974&r=dst
IIS Stability: https://bugs.php.net/fix.php?id=71974&r=isapi
Install GNU Sed: https://bugs.php.net/fix.php?id=71974&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=71974&r=float
No Zend Extensions: https://bugs.php.net/fix.php?id=71974&r=nozend
MySQL Configuration Error: https://bugs.php.net/fix.php?id=71974&r=mysqlcfg