Bug #74131 [Opn]: session.upload_progress doesn't work for database sessions

From: Date: Mon, 20 Feb 2017 11:56:23 +0000
Subject: Bug #74131 [Opn]: session.upload_progress doesn't work for database sessions
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-207463@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=74131&edit=1

 ID:                 74131
 User updated by:    fred5 at originsystems dot co dot za
 Reported by:        fred5 at originsystems dot co dot za
 Summary:            session.upload_progress doesn't work for database
                     sessions
 Status:             Open
 Type:               Bug
 Package:            Session related
 Operating System:   CentOS 7
 PHP Version:        7.0.16
 Block user comment: N
 Private report:     N

 New Comment:

Thanks very much for the candid feedback Laurence.

We are on PHP 5.6 and currently use APCu cache with apc.rfc1867 very successfully. We have provided
reliable progress bar information to our customers for some years now using this technique.

The problem for me really is as follows:

1. Your answer renders session.upload_progress useless to us (and anyone using database sessions)
See: http://stackoverflow.com/q/29867392/3051627

2. PHP 7 seems to have dropped support for apc.rfc1867 in the APCu cache.
See: http://stackoverflow.com/q/42309168/3051627

3. We support client browsers as far back as IE9, so are unable to use the new HTML5 browser
capabilities
See: https://developer.mozilla.org/en-US/docs/Using_files_from_web_applications


The combination of these things effectively means that we are unable to upgrade to PHP 7 - which is
critical for us!

I'll be honest; at the moment I'm feeling like PHP has abandoned us entirely by dropping
support for critical features without providing a workable replacement, but I am hoping that this is
a lack of knowledge on my part and that there is some tricky way of achieving a file progress bar in
PHP 7 that can both:

1. support older browsers; and 
2. work with database sessions


Is there possibly any advice you can give me that will allow us to achieve the above in PHP 7? (for
example is it possible that the apc.rfc1867 values could be made available again in APCu)

thanks again for your very prompt feedback.


Previous Comments:
------------------------------------------------------------------------
[2017-02-20 11:22:33] laruence@php.net

in that case, I understand what the problem is now. I am afraid that is no way to "fix",
because php receiving upload is ahead of any user codes being executed.

------------------------------------------------------------------------
[2017-02-20 11:16:22] fred5 at originsystems dot co dot za

thank you very much for the quick feedback!

A synopsis is as follows...

Relevant phpinfo(); configuration:
----------------------------------------------
session.save_handler	            files	files
session.save_path	            /temp/session	/temp/session
session.upload_progress.cleanup	    Off	Off
session.upload_progress.enabled	    On	On
session.upload_progress.freq	    1%	1%
session.upload_progress.min_freq    1	1
session.upload_progress.name	    PHP_SESSION_UPLOAD_PROGRESS	PHP_SESSION_UPLOAD_PROGRESS
session.upload_progress.prefix	    upload_progress_	upload_progress_

And our session handling code contains the following:

1. class Session implements SessionHandlerInterface {}
2. in Session::__construct() we set "session_set_save_handler($this,true);" (and the
following session methods Session::open,read,write etc are defined and correctly saving and
retrieving $_SESSION information from the database.

General session handling test applied:
-----------------------------------------
1. $_SESSION["test var"] = "blah blah";
This variable and value is correctly reflected serialized in the database; and
2. print $_SESSION["test var"]; prints the correct value on subsequent HTTP calls for the
same session

(no session information is stored in session.save_path folder)


Specific session.upload_progress testing
-----------------------------------------

1. On our file upload page inserted: 
<input name="PHP_SESSION_UPLOAD_PROGRESS" value="ABC"
id="PHP_SESSION_UPLOAD_PROGRESS" type="hidden">
(prior to our file input field)
<input name="af58aac50f2c132" id="af58aac50f2c132" type="file">

2. submit the form and trigger concurrent ajax progress call loop

The result / problem is as follows:

A. The ajax progress call contains "print_r($_SESSION);" . This returns returns only
"test var" and value (as above) ie. it contains no file progress information
B. At the same time, a new session file is created in session.save_path (/temp/session) containing
the following:

upload_progress_ABC|a:5:{s:10:"start_time";i:1487586588;s:14:"content_length";i:19882;s:15:"bytes_processed";i:19882;s:4:"done";b:1;s:5:"files";a:1:{i:0;a:7:{s:10:"field_name";s:15:"af58aac50f2c132";s:4:"name";s:20:"bugs.xlsx";s:8:"tmp_name";s:37:"/temp/uploads/phpCvyjWg";s:5:"error";i:0;s:4:"done";b:1;s:10:"start_time";i:1487586588;s:15:"bytes_processed";i:18795;}}}

It contains only session information relating to the upload.  (ie. the information I am expecting to
be both saved in the database and reflected in $_SESSION)

I hope this explains the problem in more detail but please let me know if I can provide further
information!

Regarding apache - here is more detail of our configuration:

# httpd -M
Loaded Modules:
 core_module (static)
 so_module (static)
 http_module (static)
 mpm_prefork_module (static)
 authn_file_module (shared)
 authn_core_module (shared)
 authz_host_module (shared)
 authz_groupfile_module (shared)
 authz_user_module (shared)
 authz_core_module (shared)
 auth_basic_module (shared)
 reqtimeout_module (shared)
 filter_module (shared)
 mime_module (shared)
 log_config_module (shared)
 env_module (shared)
 headers_module (shared)
 setenvif_module (shared)
 version_module (shared)
 unixd_module (shared)
 status_module (shared)
 autoindex_module (shared)
 dir_module (shared)
 alias_module (shared)
 php7_module (shared)
 expires_module (shared)
 rewrite_module (shared)
 socache_shmcb_module (shared)
 deflate_module (shared)
 ssl_module (shared)

------------------------------------------------------------------------
[2017-02-20 10:14:09] laruence@php.net

I can not reproduce this, please note if you are running php via fastcgi, you should disable
nginx/apache's request buffering to make this work

------------------------------------------------------------------------
[2017-02-19 21:56:50] fred5 at originsystems dot co dot za

Description:
------------
session.upload_progress always writes its $_SESSION progress information to the session.save_path
session file, ignoring session_set_save_handler settings

Therefore, if a system stores session information in the database then:

1. the database session information is not updated with the progress information; and consequently
2. print_r($_SESSION) excludes any session.upload_progress information.

Rendering session.upload_progress useless for any system using database session handling.

This has become critical as PHP 7 has stopped supporting apc.rfc1867 - which is the only reliable
alternative of which I am aware.

Please see http://stackoverflow.com/q/42315444/3051627
for more information on this if desired.



------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=74131&edit=1


Thread (12 messages)

« previous php.bugs (#207463) next »