Bug #74615 [NEW]: Unexpected session ID change on overridden SessionHandler::read() method
| From: | mikebranttx at gmail dot com | Date: | Thu, 18 May 2017 15:41:45 +0000 |
| Subject: | Bug #74615 [NEW]: Unexpected session ID change on overridden SessionHandler::read() method | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-209187@lists.php.net to get a copy of this message | ||
From: mikebranttx at gmail dot com
Operating system: Mac OSX 10.10.5
PHP version: 5.6.30
Package: Session related
Bug Type: Bug
Bug description:Unexpected session ID change on overridden SessionHandler::read() method
Description:
------------
Environment:
PHP 5.6.30_6 CLI as installed via Homebrew on Mac. (Also reproduced in
Travis CI Debian build environment with PHP 5.6.5 CLI).
xdebug 2.5.4
PHPUnit 5.7.0 (being used to run test in which error is reproduced
Loaded extensions:
bcmath, bz2, calendar, Core, ctype, curl, date, dba, dom, ereg, exif,
fileinfo, filter, ftp, gd, gettext, hash, iconv, json, ldap, libxml,
mbstring, mhash, mysql, mysqli, mysqlnd, odbc, openssl, pcntl, pcre,
PDO, pdo_mysql, PDO_ODBC, pdo_sqlite, Phar, posix, readline, Reflection,
session, shmop, SimpleXML, soap, sockets, SPL, sqlite3, standard,
sysvmsg, sysvsem, sysvshm, tokenizer, wddx, xdebug, xml, xmlreader,
xmlrpc, xmlwriter, xsl, zip, zlib
Code in which issue was surfaced is available to be installed as
composer package at -
https://packagist.org/packages/mikecbrant/php-ultimate-sessions
with source in GitHub at
https://github.com/mikecbrant/php-ultimate-sessions
Issue:
When working with a class extending SessionHandler
(UltimateSessionHandler in referenced package), There is unexpected
change of session Id within overridden read() method between the session
ID passed as argument to the method that takes place after
parent::read() is called. This happens on line 53 of
UltimateSessionHandler where parent::read() is called and can be
reproduced by either evaluating session_id() in debug session
immediately after this call or calling session_id().
This issue has only been reproduced against PHP 5.6.30 when running unit
(integration) tests. This library is tested against PHP 7.0, 7.1, and
7.2 (nightly) in CI environment and this problem is not surfaced in any
of these environments.
This may possibly be related to closed bug:
https://bugs.php.net/bug.php?id=70133&edit=2
But in my case, I am not trying to provide custom session ID, but rather
use session ID's generated by PHP.
Test script:
---------------
Pertinent part of unit test script
(tests/UltimateSessionLibraryIntegrationTest.php):
Starting at line 121:
121 $handler = new UltimateSessionHandler($handlerConfig);
...
132 $manager = new UltimateSessionManager($managerConfig,
$changeIdCallback);
...
138 $this->assertEquals('', session_id());
139 $manager->startSession();
Note the above unit test is run in an isolated process form main test
execution.
startSession() above triggers session_start() at
src/UltimateSessions/UltimateSessionsManager.php line 148, where first
line of startSession method is as follows:
148 $result = session_start();
The session_start() process then triggers UltimateSessionHandler::read()
(src/UltimateSessions/UltimateSessionHandler.php) an overridden method
for \SessionHandler::read(). The code for this method is:
50 public function read($sessionId)
51 {
52 $this->validateSessionId($sessionId);
53 $sessionData = parent::read($sessionId);
54 if($this->config->useEncryption) {
55 return $this->decrypt($sessionId, $sessionData);
56 }
57 return $sessionData;
58 }
It is after line 53 executes call to parent::read() that evaluation of
session_id() changes from value passed in method argument to a new
session ID value.
Expected result:
----------------
During session_start(), session ID passed to overridden read() method in
class extending SessionHandler would be expected to be the same as
session ID returned from session_id() call after session_start() has
completed when parent::read() is called from method.
Code works as expected in PHP 7.0.x, 7.1.x and nightly builds as shown
from most recent build -
https://travis-ci.org/mikecbrant/php-ultimate-sessions/builds/233290834
Note: you can see failed tests under PHP 5.6.5 build that relate to this
issue.
Actual result:
--------------
Immediately after call to parent::read() in overriding method, session
ID value as returned from session_id() differs from the value passed as
argument to the read() method.
--
Edit bug report at https://bugs.php.net/bug.php?id=74615&edit=1
--
Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=74615&r=trysnapshot54
Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=74615&r=trysnapshot55
Try a snapshot (trunk): https://bugs.php.net/fix.php?id=74615&r=trysnapshottrunk
Fixed in SVN: https://bugs.php.net/fix.php?id=74615&r=fixed
Fixed in release: https://bugs.php.net/fix.php?id=74615&r=alreadyfixed
Need backtrace: https://bugs.php.net/fix.php?id=74615&r=needtrace
Need Reproduce Script: https://bugs.php.net/fix.php?id=74615&r=needscript
Try newer version: https://bugs.php.net/fix.php?id=74615&r=oldversion
Not developer issue: https://bugs.php.net/fix.php?id=74615&r=support
Expected behavior: https://bugs.php.net/fix.php?id=74615&r=notwrong
Not enough info: https://bugs.php.net/fix.php?id=74615&r=notenoughinfo
Submitted twice: https://bugs.php.net/fix.php?id=74615&r=submittedtwice
register_globals: https://bugs.php.net/fix.php?id=74615&r=globals
PHP 4 support discontinued: https://bugs.php.net/fix.php?id=74615&r=php4
Daylight Savings: https://bugs.php.net/fix.php?id=74615&r=dst
IIS Stability: https://bugs.php.net/fix.php?id=74615&r=isapi
Install GNU Sed: https://bugs.php.net/fix.php?id=74615&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=74615&r=float
No Zend Extensions: https://bugs.php.net/fix.php?id=74615&r=nozend
MySQL Configuration Error: https://bugs.php.net/fix.php?id=74615&r=mysqlcfg