Bug #72997 [Ana]: Set-Cookie header lost if we do session_regenerate_id() without setcookie call

From: Date: Tue, 18 Oct 2016 06:31:17 +0000
Subject: Bug #72997 [Ana]: Set-Cookie header lost if we do session_regenerate_id() without setcookie call
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-204886@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=72997&edit=1 ID: 72997 Updated by: yohgaki@php.net Reported by: rmpic30 at gmail dot com Summary: Set-Cookie header lost if we do session_regenerate_id() without setcookie call Status: Analyzed Type: Bug Package: Session related Operating System: Irrelevant PHP Version: Irrelevant Assigned To: yohgaki Block user comment: N Private report: N New Comment: Found commit efd671f242e87e3301a1b3 Date: Wed Apr 4 16:14:28 2012 +0800 It's 4 years old. I'll ask the committer for intention. Previous Comments: ------------------------------------------------------------------------ [2016-10-18 05:05:37] yohgaki@php.net I narrowed down what's wrong. (Use CGI binary to check HTTP response headers) https://gist.github.com/yohgaki/295434c924aeaaa898689b92086378e5 Problem is that header() function removes all of previously defined 'Set-Cookie' headers blindly. header() removes any 'Set-Cookie' headers always. header() removes any 'Header' previously stored and it is not limited to 'Set-Cookie' header. I checked with git PHP 5.6. Header list operation is broken in a way to remove previous 'Header' always with header(). To work around this bug, use header() function first, then use session functions and/or setcookie(). Or do not use set HTTP header by header() that has the same name. Fix would be easy. It seems someone wrote code that remove 'Header' always with header(). ------------------------------------------------------------------------ [2016-10-17 11:47:51] yohgaki@php.net A little surprised by this bug. Verified. I suppose there is something wrong in header buffer handling. ------------------------------------------------------------------------ [2016-09-01 20:35:31] rmpic30 at gmail dot com Description: ------------ PHP does not send the Set-Cookie header, if we call session_regenerate_id() AND do not call setcookie() function for adding additional cookies. Here is plain PHP version and Symfony3 & ZF Diactoros versions. Both do not work as expected. Plain PHP version: https://gist.github.com/anonymous/6b4a906273f489e95e2dfac3c247c68c Symfony version: https://gist.github.com/anonymous/88e52bd7876378b0f490ed15d30b43fe How to reproduce (for plain PHP version): 1) Run this script on any web-server. It should return one Set-Cookie header with a new session. 2) Repeat your request with issued session. No extra Set-Cookie headers should be. 3) Run this script with parameter set_cookie with value of your current domain. You will see only ONE Set-Cookie header, header with the new PHPSESSID is lost. Now comment out line 18, and uncomment line 21 in this https://gist.github.com/anonymous/6b4a906273f489e95e2dfac3c247c68c version Repeat all steps again. On step #3 you will see TWO Set-Cookie headers as expected. $ php -v PHP 7.0.10-2+deb.sury.org~xenial+1 (cli) ( NTS ) Copyright (c) 1997-2016 The PHP Group Zend Engine v3.0.0, Copyright (c) 1998-2016 Zend Technologies with Zend OPcache v7.0.10-2+deb.sury.org~xenial+1, Copyright (c) 1999-2016, by Zend Technologies Test script: --------------- Plain PHP version: https://gist.github.com/anonymous/6b4a906273f489e95e2dfac3c247c68c Symfony version: https://gist.github.com/anonymous/88e52bd7876378b0f490ed15d30b43fe Expected result: ---------------- I should see two Set-Cookie headers on step 3. Actual result: -------------- I see only one Set-Cookie header on step 3. ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=72997&edit=1

« previous php.bugs (#204886) next »