Req #69394 [Opn]: SessionHandler should not used previously defined save handler as its base class
| From: | yohgaki@php.net | Date: | Sat, 27 Aug 2016 06:41:00 +0000 |
| Subject: | Req #69394 [Opn]: SessionHandler should not used previously defined save handler as its base class | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-203603@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=69394&edit=1
ID: 69394
Updated by: yohgaki@php.net
Reported by: deivid dot garcia dot garcia at gmail dot com
-Summary: session.save_handler incorrectly reported
+Summary: SessionHandler should not used previously defined
save handler as its base class
Status: Open
Type: Feature/Change Request
Package: Session related
Operating System: any
PHP Version: any
-Assigned To:
+Assigned To: yohgaki
Block user comment: N
Private report: N
New Comment:
First of all, previously used save handler should not be used as base of SessionHandler. It's
only useful to override save/write operation for encryption and/or session data serialization.
I would like to remove feature that SessionHandler object uses previous save handler as base class.
To do that, we need "user defined serialize handler". There is implementation for this
already. This feature was not implemented because of register_globals when session module is
implemented.
Previous Comments:
------------------------------------------------------------------------
[2015-04-07 13:19:02] deivid dot garcia dot garcia at gmail dot com
Description:
------------
When using the SessionHandler class (that as per documentation wraps over the current native handler
set in session.save_handler)to override the session handler with session_set_save_handler() PHP
starts reporting that the session.save_handler is "user" after the override.
I can understand that this will happen when using a custom class that implements
SessionHandlerInterface or directly passing custom methods to session_set_save_handler, but because
we are wrapping over the underlying handler it would be better to report the original
session.save_handler when doing an ini_get().
This could be further improved while keeping current behaviour if SessionHandlerInterface exposed a
property or function where the Handler could report its name.
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=69394&edit=1