Edit report at https://bugs.php.net/bug.php?id=65746&edit=1
ID: 65746
Updated by: yohgaki@php.net
Reported by: yohgaki@php.net
-Summary: session_regenerate_id() does not delete old session
data.
+Summary: session_regenerate_id() should not delete old
session data immediately.
Status: Analyzed
Type: Feature/Change Request
Package: Session related
PHP Version: 5.5Git-2013-09-23 (Git)
Assigned To: yohgaki
Block user comment: N
Private report: N
New Comment:
Use proper title. Original title meant "no deletion by __default__".
Last RFC is declined, but we _MUST_ fix this issue.
session_regenerate_id() depreciation is a option. We shouldn't keep security related broken
function.
Previous Comments:
------------------------------------------------------------------------
[2015-09-29 02:07:59] yohgaki@php.net
Related RFC
https://wiki.php.net/rfc/precise_session_management
------------------------------------------------------------------------
[2015-07-11 20:45:00] ab@php.net
Related To: Bug #70013
------------------------------------------------------------------------
[2015-05-24 06:21:56] yohgaki@php.net
Patch was there, but there are some objections for lazy destroy. I think there is no objection now.
This bug is related to
https://bugs.php.net/bug.php?id=69127
------------------------------------------------------------------------
[2014-03-12 11:44:18] narf at devilix dot net
Huh, well ... it was last discussed 4 months ago and the RFC hasn't been updated since.
------------------------------------------------------------------------
[2014-03-12 06:43:25] yohgaki@php.net
Unfortunately no.
To delete old session properly, old session data should be deleted after a while. This behavior is
under discussion now.
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=65746
--
Edit this bug report at https://bugs.php.net/bug.php?id=65746&edit=1