Bug #75554 [NEW]: session_regenerate_id() causes duplicate Set-Cookie header to be sent
| From: | arve at coretrek dot no | Date: | Wed, 22 Nov 2017 12:37:29 +0000 |
| Subject: | Bug #75554 [NEW]: session_regenerate_id() causes duplicate Set-Cookie header to be sent | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-212678@lists.php.net to get a copy of this message | ||
From: arve at coretrek dot no
Operating system: Linux Mint 18, Ubuntu 12.04 LTS
PHP version: 7.1.11
Package: Session related
Bug Type: Bug
Bug description:session_regenerate_id() causes duplicate Set-Cookie header to be sent
Description:
------------
When calling session_start() and then session_regenerate_id(), PHP will
send two Set-Cookie headers, one containing the old session id and the
other containing the new session id.
Testet on:
* PHP 7.1.11 on Ubuntu 12.04 (installed via phpbrew)
* PHP 7.0.22-0ubuntu0.16.04.1 on Linux Mint 18
Test script:
---------------
First, create sessiontest.php:
<?php
session_start();
if (!isset($_SESSION['SessionInitiated'])) {
session_regenerate_id();
$_SESSION['SessionInitiated'] = true;
}
?>
Then, access sessiontest.php through Apache and inspect response
headers, e.g. by using curl:
curl -sv http://localhost/sessiontest.php >
/dev/null
* Trying 127.0.1.1...
* Connected to localhost (127.0.1.1) port 80 (#0)
> GET /sessiontest.php HTTP/1.1
> Host: localhost
> User-Agent: curl/7.47.0
> Accept: */*
>
< HTTP/1.1 200 OK
< Date: Wed, 22 Nov 2017 12:07:52 GMT
< Server: Apache/2.4.18 (Ubuntu)
< Set-Cookie: PHPSESSID=8676mem4p76uka76ta2qq072q1; path=/
< Expires: Thu, 19 Nov 1981 08:52:00 GMT
< Cache-Control: no-store, no-cache, must-revalidate
< Pragma: no-cache
< Set-Cookie: PHPSESSID=rvud0d79be3oa77rnbag0lmgc2; path=/
< Content-Length: 0
< Content-Type: text/html; charset=UTF-8
Expected result:
----------------
Only send one Set-Cookie header (containing the new session id).
Actual result:
--------------
Two Set-Cookie headers are sent, one containing the old session id and
the other containing the new session id. This confuses browsers and
cause some browsers to continue using the old session cookie.
In addition, if you call var_dump(headers_list()) at the end of the
script, only ONE Set-Cookie header will be listed here, even though two
headers are sent.
--
Edit bug report at https://bugs.php.net/bug.php?id=75554&edit=1
--
Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=75554&r=trysnapshot54
Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=75554&r=trysnapshot55
Try a snapshot (trunk): https://bugs.php.net/fix.php?id=75554&r=trysnapshottrunk
Fixed in SVN: https://bugs.php.net/fix.php?id=75554&r=fixed
Fixed in release: https://bugs.php.net/fix.php?id=75554&r=alreadyfixed
Need backtrace: https://bugs.php.net/fix.php?id=75554&r=needtrace
Need Reproduce Script: https://bugs.php.net/fix.php?id=75554&r=needscript
Try newer version: https://bugs.php.net/fix.php?id=75554&r=oldversion
Not developer issue: https://bugs.php.net/fix.php?id=75554&r=support
Expected behavior: https://bugs.php.net/fix.php?id=75554&r=notwrong
Not enough info: https://bugs.php.net/fix.php?id=75554&r=notenoughinfo
Submitted twice: https://bugs.php.net/fix.php?id=75554&r=submittedtwice
register_globals: https://bugs.php.net/fix.php?id=75554&r=globals
PHP 4 support discontinued: https://bugs.php.net/fix.php?id=75554&r=php4
Daylight Savings: https://bugs.php.net/fix.php?id=75554&r=dst
IIS Stability: https://bugs.php.net/fix.php?id=75554&r=isapi
Install GNU Sed: https://bugs.php.net/fix.php?id=75554&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=75554&r=float
No Zend Extensions: https://bugs.php.net/fix.php?id=75554&r=nozend
MySQL Configuration Error: https://bugs.php.net/fix.php?id=75554&r=mysqlcfg