Bug #38104 [Com]: session_start()/session_write_close() creates multiple session cookies headers

From: Date: Tue, 11 Apr 2017 02:19:03 +0000
Subject: Bug #38104 [Com]: session_start()/session_write_close() creates multiple session cookies headers
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-208463@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=38104&edit=1 ID: 38104 Comment by: dapphp at sonic dot net Reported by: m dot v dot veluw dot smscity at gmail dot com Summary: session_start()/session_write_close() creates multiple session cookies headers Status: Closed Type: Bug Package: Session related Operating System: any PHP Version: 5.1.4 Assigned To: yohgaki Block user comment: N Private report: N New Comment: I also just ran into this issue on PHP 5.6.30-7+deb.sury.org so if it was fixed it would be nice to know which version it was fixed in. I have a long running download process kicked off from an Ajax request to PHP that updates state every few seconds to $_SESSION that calls session_start() before each update and session_write_close() after. Subsequent Ajax calls to check state are sent every few seconds by the browser. Longer requests would never seem to terminate and it was because hundreds or more Set-Cookie lines with the same session_id were being sent. The browser or Ajax stack couldn't handle all the header data (but no PHP or browser script errors). PHP source didn't yield any solutions but revealed a workaround. In the long running script, add this before the later session_start() calls: ini_set('session.use_cookies', 0); At the very least PHP sees this setting when calling session_start() and will not append additional session ID cookies to the response. This fixed the issue for me. Previous Comments: ------------------------------------------------------------------------ [2016-08-01 19:14:21] dvrs at brtdv dot 33mail dot com I'm having this same issue... A session_write_reopen($session_id) function would easily solve this issue imho. I don't see how this is taking 10 years to solve. A workaround to this issue would be passing the "session.use_cookies" as false in the $options argument the 2nd time you use session_start(). This off course would only work for users of PHP7. ------------------------------------------------------------------------ [2016-04-18 18:54:11] ericovasconcelos at gmail dot com How this issue was fixed? I'm facing the same situation now. ------------------------------------------------------------------------ [2015-08-11 10:36:38] yohgaki@php.net Time goes by. I fixed this already. If you have problem, please open new bug report. ------------------------------------------------------------------------ [2015-08-10 20:18:18] waldoc at latinmail dot com A LOT of people is using session_start(); and session_write_close(); as a way to update $_SESSION data and make it available for other scripts (usually called using AJAX) The problem is session_start(); and his SEND HEADERS AGAIN Feature. So the solution is simple: Add a new function called session_write_open(); in order to be used with session_write_close(); Headers are only set by session_start(), and session_write_open() will resume that session without sending headers again. If that solution is too complicated, then add a new option to the session_start(); ie: session_start(MUTE_HEADERS) that restore the session without send headers again. I'm pretty sure that the second implementation is even more easy and fast to implement, because if MUTE_HEADERS are set, then you got to skip the send header part of the function. Hope this features will be present in the next release. Best regards ------------------------------------------------------------------------ [2015-02-02 17:09:53] yohgaki@php.net If only one header is sent, multiple sessions cannot be used. Therefore, it will not be fixed. ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=38104 -- Edit this bug report at https://bugs.php.net/bug.php?id=38104&edit=1

« previous php.bugs (#208463) next »