Bug #75554 [NEW]: session_regenerate_id() causes duplicate Set-Cookie header to be sent

From: Date: Wed, 22 Nov 2017 12:37:29 +0000
Subject: Bug #75554 [NEW]: session_regenerate_id() causes duplicate Set-Cookie header to be sent
Groups: php.bugs 
Request: Send a blank email to php-bugs+get-212678@lists.php.net to get a copy of this message
From: arve at coretrek dot no Operating system: Linux Mint 18, Ubuntu 12.04 LTS PHP version: 7.1.11 Package: Session related Bug Type: Bug Bug description:session_regenerate_id() causes duplicate Set-Cookie header to be sent Description: ------------ When calling session_start() and then session_regenerate_id(), PHP will send two Set-Cookie headers, one containing the old session id and the other containing the new session id. Testet on: * PHP 7.1.11 on Ubuntu 12.04 (installed via phpbrew) * PHP 7.0.22-0ubuntu0.16.04.1 on Linux Mint 18 Test script: --------------- First, create sessiontest.php: <?php session_start(); if (!isset($_SESSION['SessionInitiated'])) { session_regenerate_id(); $_SESSION['SessionInitiated'] = true; } ?> Then, access sessiontest.php through Apache and inspect response headers, e.g. by using curl: curl -sv http://localhost/sessiontest.php > /dev/null * Trying 127.0.1.1... * Connected to localhost (127.0.1.1) port 80 (#0) > GET /sessiontest.php HTTP/1.1 > Host: localhost > User-Agent: curl/7.47.0 > Accept: */* > < HTTP/1.1 200 OK < Date: Wed, 22 Nov 2017 12:07:52 GMT < Server: Apache/2.4.18 (Ubuntu) < Set-Cookie: PHPSESSID=8676mem4p76uka76ta2qq072q1; path=/ < Expires: Thu, 19 Nov 1981 08:52:00 GMT < Cache-Control: no-store, no-cache, must-revalidate < Pragma: no-cache < Set-Cookie: PHPSESSID=rvud0d79be3oa77rnbag0lmgc2; path=/ < Content-Length: 0 < Content-Type: text/html; charset=UTF-8 Expected result: ---------------- Only send one Set-Cookie header (containing the new session id). Actual result: -------------- Two Set-Cookie headers are sent, one containing the old session id and the other containing the new session id. This confuses browsers and cause some browsers to continue using the old session cookie. In addition, if you call var_dump(headers_list()) at the end of the script, only ONE Set-Cookie header will be listed here, even though two headers are sent. -- Edit bug report at https://bugs.php.net/bug.php?id=75554&edit=1 -- Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=75554&r=trysnapshot54 Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=75554&r=trysnapshot55 Try a snapshot (trunk): https://bugs.php.net/fix.php?id=75554&r=trysnapshottrunk Fixed in SVN: https://bugs.php.net/fix.php?id=75554&r=fixed Fixed in release: https://bugs.php.net/fix.php?id=75554&r=alreadyfixed Need backtrace: https://bugs.php.net/fix.php?id=75554&r=needtrace Need Reproduce Script: https://bugs.php.net/fix.php?id=75554&r=needscript Try newer version: https://bugs.php.net/fix.php?id=75554&r=oldversion Not developer issue: https://bugs.php.net/fix.php?id=75554&r=support Expected behavior: https://bugs.php.net/fix.php?id=75554&r=notwrong Not enough info: https://bugs.php.net/fix.php?id=75554&r=notenoughinfo Submitted twice: https://bugs.php.net/fix.php?id=75554&r=submittedtwice register_globals: https://bugs.php.net/fix.php?id=75554&r=globals PHP 4 support discontinued: https://bugs.php.net/fix.php?id=75554&r=php4 Daylight Savings: https://bugs.php.net/fix.php?id=75554&r=dst IIS Stability: https://bugs.php.net/fix.php?id=75554&r=isapi Install GNU Sed: https://bugs.php.net/fix.php?id=75554&r=gnused Floating point limitations: https://bugs.php.net/fix.php?id=75554&r=float No Zend Extensions: https://bugs.php.net/fix.php?id=75554&r=nozend MySQL Configuration Error: https://bugs.php.net/fix.php?id=75554&r=mysqlcfg

« previous php.bugs (#212678) next »