Edit report at https://bugs.php.net/bug.php?id=72940&edit=1
ID: 72940
User updated by: archinf at archinform dot de
Reported by: archinf at archinform dot de
Summary: SID always return "name=ID", even if session cookie
exists
Status: Assigned
Type: Bug
Package: Session related
PHP Version: 7.0.10
Assigned To: yohgaki
Block user comment: N
Private report: N
New Comment:
@yohgaki: Thanks, as workaround I check for the meanwhile session cookie existence (and SID match)
with something like
...if(!((isset($_COOKIE[session_name()]))&&($_COOKIE[session_name()]==session_id()))){...
Previous Comments:
------------------------------------------------------------------------
[2016-08-27 07:37:36] yohgaki@php.net
I'll fix this because some users may be relying on the feature that SID being empty when there
is session ID cookie.
------------------------------------------------------------------------
[2016-08-27 05:10:05] yohgaki@php.net
It's oversight. However, IMHO SID should be always defined as it might break apps define SID
constant.
------------------------------------------------------------------------
[2016-08-25 11:00:42] archinf at archinform dot de
@cmb.php.net:
in bug #71974 session.use_trans_sid is set to 1 (in my case 0)
------------------------------------------------------------------------
[2016-08-25 10:54:26] archinf at archinform dot de
php.ini main session related settings:
session.save_handler = files
session.use_strict_mode = 0
session.use_cookies = 1
session.use_only_cookies = 0
session.name = ID
session.auto_start = 0
session.use_trans_sid = 0
------------------------------------------------------------------------
[2016-08-25 10:43:24] cmb@php.net
That might be related to bug #71974.
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=72940
--
Edit this bug report at https://bugs.php.net/bug.php?id=72940&edit=1