Bug #38104 [Com]: session_start()/session_write_close() creates multiple session cookies headers
| From: | dapphp at sonic dot net | Date: | Tue, 11 Apr 2017 02:19:03 +0000 |
| Subject: | Bug #38104 [Com]: session_start()/session_write_close() creates multiple session cookies headers | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-208463@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=38104&edit=1
ID: 38104
Comment by: dapphp at sonic dot net
Reported by: m dot v dot veluw dot smscity at gmail dot com
Summary: session_start()/session_write_close() creates
multiple session cookies headers
Status: Closed
Type: Bug
Package: Session related
Operating System: any
PHP Version: 5.1.4
Assigned To: yohgaki
Block user comment: N
Private report: N
New Comment:
I also just ran into this issue on PHP 5.6.30-7+deb.sury.org so if it was fixed it would be nice to
know which version it was fixed in.
I have a long running download process kicked off from an Ajax request to PHP that updates state
every few seconds to $_SESSION that calls session_start() before each update and
session_write_close() after. Subsequent Ajax calls to check state are sent every few seconds by the
browser.
Longer requests would never seem to terminate and it was because hundreds or more Set-Cookie lines
with the same session_id were being sent. The browser or Ajax stack couldn't handle all the
header data (but no PHP or browser script errors).
PHP source didn't yield any solutions but revealed a workaround.
In the long running script, add this before the later session_start() calls:
ini_set('session.use_cookies', 0);
At the very least PHP sees this setting when calling session_start() and will not append additional
session ID cookies to the response. This fixed the issue for me.
Previous Comments:
------------------------------------------------------------------------
[2016-08-01 19:14:21] dvrs at brtdv dot 33mail dot com
I'm having this same issue... A session_write_reopen($session_id) function would easily solve
this issue imho. I don't see how this is taking 10 years to solve.
A workaround to this issue would be passing the "session.use_cookies" as false in the
$options argument the 2nd time you use session_start(). This off course would only work for users of
PHP7.
------------------------------------------------------------------------
[2016-04-18 18:54:11] ericovasconcelos at gmail dot com
How this issue was fixed? I'm facing the same situation now.
------------------------------------------------------------------------
[2015-08-11 10:36:38] yohgaki@php.net
Time goes by.
I fixed this already. If you have problem, please open new bug report.
------------------------------------------------------------------------
[2015-08-10 20:18:18] waldoc at latinmail dot com
A LOT of people is using session_start(); and session_write_close(); as a way to update $_SESSION
data and make it available for other scripts (usually called using AJAX)
The problem is session_start(); and his SEND HEADERS AGAIN Feature.
So the solution is simple:
Add a new function called session_write_open(); in order to be used with session_write_close();
Headers are only set by session_start(), and session_write_open() will resume that session without
sending headers again.
If that solution is too complicated, then add a new option to the session_start(); ie:
session_start(MUTE_HEADERS) that restore the session without send headers again.
I'm pretty sure that the second implementation is even more easy and fast to implement, because
if MUTE_HEADERS are set, then you got to skip the send header part of the function.
Hope this features will be present in the next release.
Best regards
------------------------------------------------------------------------
[2015-02-02 17:09:53] yohgaki@php.net
If only one header is sent, multiple sessions cannot be used. Therefore, it will not be fixed.
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=38104
--
Edit this bug report at https://bugs.php.net/bug.php?id=38104&edit=1