Bug #72940 [Csd]: SID always return "name=ID", even if session cookie exists

From: Date: Tue, 30 Aug 2016 07:27:40 +0000
Subject: Bug #72940 [Csd]: SID always return "name=ID", even if session cookie exists
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-203668@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=72940&edit=1

 ID:                 72940
 Updated by:         yohgaki@php.net
 Reported by:        archinf at archinform dot de
 Summary:            SID always return "name=ID", even if session cookie
                     exists
 Status:             Closed
 Type:               Bug
 Package:            Session related
 PHP Version:        7.0.10
 Assigned To:        yohgaki
 Block user comment: N
 Private report:     N

 New Comment:

Cookie has priority when session.use_cookies=1.


Previous Comments:
------------------------------------------------------------------------
[2016-08-30 07:01:10] yohgaki@php.net

Automatic comment on behalf of yohgaki
Revision: http://git.php.net/?p=php-src.git;a=commit;h=b5f2f6fbd802ad3bc4fb37185e9e776bb089db56
Log: Fixed bug #72940 SID always return "name=ID", even if session cookie exist

------------------------------------------------------------------------
[2016-08-29 09:19:39] archinf at archinform dot de

On dealing with SID following further question araised: What happens if session id is defined by
cookie AND Url parameter (with different values)? Does PHP any kind of predefined priority/error
handling in such a case?

------------------------------------------------------------------------
[2016-08-29 09:08:18] archinf at archinform dot de

@yohgaki: Thanks, as workaround I check for the meanwhile session cookie existence (and SID match)
with something like
...if(!((isset($_COOKIE[session_name()]))&&($_COOKIE[session_name()]==session_id()))){...

------------------------------------------------------------------------
[2016-08-27 07:37:36] yohgaki@php.net

I'll fix this because some users may be relying on the feature that SID being empty when there
is session ID cookie.

------------------------------------------------------------------------
[2016-08-27 05:10:05] yohgaki@php.net

It's oversight. However, IMHO SID should be always defined as it might break apps define SID
constant.

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=72940


--
Edit this bug report at https://bugs.php.net/bug.php?id=72940&edit=1


Thread (10 messages)

« previous php.bugs (#203668) next »