Bug #74985 [Com]: Session timeout limited to 1440 seconds!
| From: | spam2 at rhsoft dot net | Date: | Sat, 12 Aug 2017 15:05:41 +0000 |
| Subject: | Bug #74985 [Com]: Session timeout limited to 1440 seconds! | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-210634@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=74985&edit=1
ID: 74985
Comment by: spam2 at rhsoft dot net
Reported by: matthew at slyman dot org
Summary: Session timeout limited to 1440 seconds!
Status: Open
Type: Bug
Package: *General Issues
PHP Version: 7.1.7
Block user comment: N
Private report: N
New Comment:
doing that with ini_set() is flawed by design - you can't expect any useful behavior when some
scripts use the ini-settings, some per vhost and others mange with ini_set() because the workers are
shared between all the incarnations of settings and so you are playing finally lottery
what do you think happens when the next request handles a different script and hat has a lower value
- GC is started and your sessions from other requests are purged too
hence normally it should be prohibited (php_admin_value in the vhost config which no longer allows
to change values from scripts) and when you have different settings for vhosts each of them has tu
ose it's own exclusive session_save_path
anyways, it's a poor "to work out of the box" default select a radnom wroker which
has to handle a request for cleaup a directory with probably many thousand of files and so on
serious production machines the session GC of PHP is disabled at all and the cleanup done with
cronjobs calling something like "find /var/www/sessiondata -type f -mmin +30 -delete"
which under load also makes sure that "session.gc_probability" hits probably a dozen of
processes doing concurrent cleanup - set it to 0 and do it proper with a cronjob
Previous Comments:
------------------------------------------------------------------------
[2017-08-12 14:45:01] ajf@php.net
Have you tried changing the INI file directly, rather than at runtime?
------------------------------------------------------------------------
[2017-07-25 06:38:31] matthew at slyman dot org
Description:
------------
With the following session configuration, I get the desired 2 hour sessions in PHP7.0 â but in
PHP7.1, sessions seem to be limited to a much shorter time, e.g. 900â1440 seconds, despite my
attempt to reconfigure this: PHP7.1 seems to be ignoring my instructions about how long sessions
should last for! I realise that session garbage collection has been changed. Is there a bug in PHP,
or have I forgotten to configure something in the new system?
Test script:
---------------
\ini_set('session.use_only_cookies',1);
\ini_set('session.use_strict_mode',1); \ini_set('session.gc_maxlifetime',7200);//2
hour sessions
\ini_set('session.cookie_httponly',1);
\ini_set('session.cookie_secure',1);
\ini_set('session.cookie_lifetime',0);
\ini_set('session.hash_function','sha256');//Does nothing in PHP7.1
\ini_set('session.hash_bits_per_character','4');//Does nothing in PHP7.1
\ini_set('session.sid_length',64);//PHP7.1
\ini_set('session.sid_bits_per_character',4);//PHP7.1
\session_start();
Expected result:
----------------
Sessions should last for 2 hours (7200s).
Actual result:
--------------
Sessions last for â¤1440 seconds before garbage collection occurs, which logs out users before
they can complete certain actions, e.g. completing extended psychometric profile questionnaires
(large HTML forms).
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=74985&edit=1