Bug #71599 [Csd]: trans sid handling rework broke interaction with cookies
| From: | phpbug at wisl dot de | Date: | Wed, 06 Apr 2016 10:22:54 +0000 |
| Subject: | Bug #71599 [Csd]: trans sid handling rework broke interaction with cookies | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-200409@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=71599&edit=1
ID: 71599
User updated by: phpbug at wisl dot de
Reported by: phpbug at wisl dot de
Summary: trans sid handling rework broke interaction with
cookies
Status: Closed
Type: Bug
Package: Session related
Operating System: All
PHP Version: 7.0.3
Assigned To: yohgaki
Block user comment: N
Private report: N
New Comment:
[2016-04-06 00:17 UTC] yohgaki@php.net
>The issue mentioned on this bug report is crash bug that is caused by missing
>>zend_is_auto_global(). This is fixed.
I am the original reporter. And the original report was about the cookie problems. That's why
this bug has "trans sid handling rework broke interaction with cookies" as its subject.
I only mentioned the crash, because when trying to debug this issue I suddenly only got HTTP 500
from my local server, because now the php-cgi was crashing.
My Bug https://bugs.php.net/bug.php?id=71754 is
a duplicate of Bug #71683, because I did not really search when filing this bug, because the main
intention behind Bug #71754 was to get any attention, because this bug had been completely ignored
for nearly a complete month. OTOH #71754 demonstrated that this crash did not only happen in cli,
but also in the cgi version of PHP.
>Please open new bug report for this and keep this one closed. I think I >understand what is
>your problem, but please describe the issue in detail. >Thank you.
I will report a new bug to disentangle this...
[2016-04-06 00:33 UTC] yohgaki@php.net
>BTW, issue you're describing sounds like known issue (at least for me) for a >long time.
>To make sure it is known issue, please write short reproducible >code.
It is a clear regression between PHP5 and PHP7, as described at various comments. And a single Test
script, including "Expected result" and "Actual result" was provided in the
original bug report.
Previous Comments:
------------------------------------------------------------------------
[2016-04-06 00:33:22] yohgaki@php.net
BTW, issue you're describing sounds like known issue (at least for me) for a long time. To make
sure it is known issue, please write short reproducible code.
------------------------------------------------------------------------
[2016-04-06 00:17:47] yohgaki@php.net
The issue mentioned on this bug report is crash bug that is caused by missing zend_is_auto_global().
This is fixed.
Please open new bug report for this and keep this one closed. I think I understand what is your
problem, but please describe the issue in detail. Thank you.
------------------------------------------------------------------------
[2016-04-05 14:59:01] phpbug at wisl dot de
PHP 7.0.5 just appeared in the Gentoo package tree and I retested this version.
The main bug, the broken interaction between trans sid and cookies, is *NOT* fixed, it still has the
same regressions.
1.: https://github.com/php/php-src/commit/f248df900300c5b2201d4cf634d58d413399e2eb#diff-52eb9eb7f9d5d9125fbb1337a6541c06L538
By removing the condition " && PS(send_cookie)" before apply_trans_sid was set 1,
now a trans sid will always be transmitted, even if a correct session cookie is available. That
prevents using the trans sid as a simple fallback, because as of PHP7 if it is enabled at all, it
will always send an PHPSESSID rendering any cookie support superfluous despite using cookies for
session ids is the better way.
2.: https://github.com/php/php-src/commit/f248df900300c5b2201d4cf634d58d413399e2eb#diff-52eb9eb7f9d5d9125fbb1337a6541c06L1494
By no longer resetting the rewriter each call to php_session_reset_id() will add another PHPSESSID
parameter instead of replacing the old one.
As session_regenerate_id() is calling into this function when switching to a new session id this
means, that each call to session_regenerate_id() will add another PHPSESSID parameter.
For me this means, that if a visitor request the first page of my site an new session will be
generated. This will add a first PHPSESSID parameter to all URLs. This new empty session will be
regarded as unsafe, by my code, because its ID might have been supplied by an attacker. So my code
calls session_regenerate_id() to generate a new, guaranteed to be safe, session id. This will now
add a second PHPSESSID parameter, while leaving the original (possible tampered with ID) in all
URLs. PHP version before PHP7 would correctly only insert the correct new session id.
Both of these changes are serious regression for my code, as it means I can no longer use the trans
sid in PHP7 and now need to force all my visitors to enable cookies. As the commit promised
"Behavior is unchanged", I see this as bugs and not changes that were needed to make PHP7
work, so please restore the trans sid behavior as it was in PHP5.
------------------------------------------------------------------------
[2016-03-14 14:59:30] ab@php.net
Automatic comment on behalf of yohgaki
Revision: http://git.php.net/?p=php-src.git;a=commit;h=ca61f5954bf9e64072bfa31b4a7431e211a109e7
Log: Fixed Bug #71754 Regression in PHP7.0: trivial script segfaults php-cgi Fixed Bug #71683 Null
pointer dereference in zend_hash_str_find_bucket Fixed Bug #71599 trans sid handling rework broke
interaction with cookies
------------------------------------------------------------------------
[2016-03-11 23:43:33] yohgaki@php.net
Automatic comment on behalf of yohgaki
Revision: http://git.php.net/?p=php-src.git;a=commit;h=ca61f5954bf9e64072bfa31b4a7431e211a109e7
Log: Fixed Bug #71754 Regression in PHP7.0: trivial script segfaults php-cgi Fixed Bug #71683 Null
pointer dereference in zend_hash_str_find_bucket Fixed Bug #71599 trans sid handling rework broke
interaction with cookies
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=71599
--
Edit this bug report at https://bugs.php.net/bug.php?id=71599&edit=1