Bug #72997 [Asn->Ana]: Set-Cookie header lost if we do session_regenerate_id() without setcookie call
| From: | yohgaki@php.net | Date: | Tue, 18 Oct 2016 05:05:44 +0000 |
| Subject: | Bug #72997 [Asn->Ana]: Set-Cookie header lost if we do session_regenerate_id() without setcookie call | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-204885@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=72997&edit=1
ID: 72997
Updated by: yohgaki@php.net
Reported by: rmpic30 at gmail dot com
Summary: Set-Cookie header lost if we do
session_regenerate_id() without setcookie call
-Status: Assigned
+Status: Analyzed
Type: Bug
Package: Session related
Operating System: Irrelevant
PHP Version: Irrelevant
Assigned To: yohgaki
Block user comment: N
Private report: N
New Comment:
I narrowed down what's wrong.
(Use CGI binary to check HTTP response headers)
https://gist.github.com/yohgaki/295434c924aeaaa898689b92086378e5
Problem is that header() function removes all of previously defined 'Set-Cookie' headers
blindly. header() removes any 'Set-Cookie' headers always.
header() removes any 'Header' previously stored and it is not limited to
'Set-Cookie' header.
I checked with git PHP 5.6. Header list operation is broken in a way to remove previous
'Header' always with header().
To work around this bug, use header() function first, then use session functions and/or setcookie().
Or do not use set HTTP header by header() that has the same name.
Fix would be easy. It seems someone wrote code that remove 'Header' always with header().
Previous Comments:
------------------------------------------------------------------------
[2016-10-17 11:47:51] yohgaki@php.net
A little surprised by this bug. Verified.
I suppose there is something wrong in header buffer handling.
------------------------------------------------------------------------
[2016-09-01 20:35:31] rmpic30 at gmail dot com
Description:
------------
PHP does not send the
Set-Cookie header, if we call
session_regenerate_id() AND do not call setcookie() function for adding
additional cookies.
Here is plain PHP version and Symfony3 & ZF Diactoros versions. Both do not work as expected.
Plain PHP version: https://gist.github.com/anonymous/6b4a906273f489e95e2dfac3c247c68c
Symfony version: https://gist.github.com/anonymous/88e52bd7876378b0f490ed15d30b43fe
How to reproduce (for plain PHP version):
1) Run this script on any web-server. It should return one Set-Cookie header with a new
session.
2) Repeat your request with issued session. No extra Set-Cookie headers should be.
3) Run this script with parameter set_cookie with value of your current domain. You
will see only ONE Set-Cookie header, header with the new PHPSESSID is lost.
Now comment out line 18, and uncomment line 21 in this https://gist.github.com/anonymous/6b4a906273f489e95e2dfac3c247c68c
version
Repeat all steps again. On step #3 you will see TWO Set-Cookie headers as expected.
$ php -v
PHP 7.0.10-2+deb.sury.org~xenial+1 (cli) ( NTS )
Copyright (c) 1997-2016 The PHP Group
Zend Engine v3.0.0, Copyright (c) 1998-2016 Zend Technologies
with Zend OPcache v7.0.10-2+deb.sury.org~xenial+1, Copyright (c) 1999-2016, by Zend Technologies
Test script:
---------------
Plain PHP version: https://gist.github.com/anonymous/6b4a906273f489e95e2dfac3c247c68c
Symfony version: https://gist.github.com/anonymous/88e52bd7876378b0f490ed15d30b43fe
Expected result:
----------------
I should see two Set-Cookie headers on step 3.
Actual result:
--------------
I see only one Set-Cookie header on step 3.
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=72997&edit=1