Bug #38104 [Com]: session_start()/session_write_close() creates multiple session cookies headers

From: Date: Mon, 01 Aug 2016 19:14:24 +0000
Subject: Bug #38104 [Com]: session_start()/session_write_close() creates multiple session cookies headers
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-202807@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=38104&edit=1 ID: 38104 Comment by: dvrs at brtdv dot 33mail dot com Reported by: m dot v dot veluw dot smscity at gmail dot com Summary: session_start()/session_write_close() creates multiple session cookies headers Status: Closed Type: Bug Package: Session related Operating System: any PHP Version: 5.1.4 Assigned To: yohgaki Block user comment: N Private report: N New Comment: I'm having this same issue... A session_write_reopen($session_id) function would easily solve this issue imho. I don't see how this is taking 10 years to solve. A workaround to this issue would be passing the "session.use_cookies" as false in the $options argument the 2nd time you use session_start(). This off course would only work for users of PHP7. Previous Comments: ------------------------------------------------------------------------ [2016-04-18 18:54:11] ericovasconcelos at gmail dot com How this issue was fixed? I'm facing the same situation now. ------------------------------------------------------------------------ [2015-08-11 10:36:38] yohgaki@php.net Time goes by. I fixed this already. If you have problem, please open new bug report. ------------------------------------------------------------------------ [2015-08-10 20:18:18] waldoc at latinmail dot com A LOT of people is using session_start(); and session_write_close(); as a way to update $_SESSION data and make it available for other scripts (usually called using AJAX) The problem is session_start(); and his SEND HEADERS AGAIN Feature. So the solution is simple: Add a new function called session_write_open(); in order to be used with session_write_close(); Headers are only set by session_start(), and session_write_open() will resume that session without sending headers again. If that solution is too complicated, then add a new option to the session_start(); ie: session_start(MUTE_HEADERS) that restore the session without send headers again. I'm pretty sure that the second implementation is even more easy and fast to implement, because if MUTE_HEADERS are set, then you got to skip the send header part of the function. Hope this features will be present in the next release. Best regards ------------------------------------------------------------------------ [2015-02-02 17:09:53] yohgaki@php.net If only one header is sent, multiple sessions cannot be used. Therefore, it will not be fixed. ------------------------------------------------------------------------ [2014-09-10 10:29:27] yohgaki@php.net I don't remember well, but I think I've dealt "multiple cookies" issue partially. I might not for this case. I'll fix it sends multiple cookies, please let us know. Unfortunately, PHP does not make sure that old session is not deleted. If old session was authenticated before session regeneration, bad luck. (We could still say "it's users fault", though) To remove old session, it must be deleted asynchronous manner. However, few people against this change and insist synchronous deletion which cannot be done. (i.e. Web server and client is _not_ synchronized, thus synchronous deletion can cause serious problem) Anyway, please update PHP version if there is issue. If not, please close this again. Thank you. ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=38104 -- Edit this bug report at https://bugs.php.net/bug.php?id=38104&edit=1

« previous php.bugs (#202807) next »