Bug #75554 [Com]: session_regenerate_id() causes duplicate Set-Cookie header to be sent
| From: | pmmaga@php.net | Date: | Tue, 01 May 2018 20:12:42 +0000 |
| Subject: | Bug #75554 [Com]: session_regenerate_id() causes duplicate Set-Cookie header to be sent | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-214999@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=75554&edit=1
ID: 75554
Comment by: pmmaga@php.net
Reported by: arve at coretrek dot no
Summary: session_regenerate_id() causes duplicate Set-Cookie
header to be sent
Status: Analyzed
Type: Bug
Package: Apache2 related
Operating System: Linux Mint 18, Ubuntu 12.04 LTS
PHP Version: 7.1.11
Assigned To: pmmaga
Block user comment: N
Private report: N
New Comment:
Not able to link the PR at the moment. Here's the link: https://github.com/php/php-src/pull/3231
Previous Comments:
------------------------------------------------------------------------
[2018-05-01 20:02:17] pmmaga@php.net
This bug is specific to apache2. I have looked into it and have created a PR with a potential fix.
You can find more details on the PR itself.
------------------------------------------------------------------------
[2018-04-10 17:14:19] tilmann dot bach at telekom dot de
I can confirm this BUG. This behavior is in contrast to the RFC: https://tools.ietf.org/html/rfc6265#section-4.1.1
"Servers SHOULD NOT include more than one Set-Cookie header field in the same response with the
same cookie-name. (See Section 5.2 for how user agents handle this case.)"
------------------------------------------------------------------------
[2017-11-22 12:37:24] arve at coretrek dot no
Description:
------------
When calling session_start() and then session_regenerate_id(), PHP will send two Set-Cookie headers,
one containing the old session id and the other containing the new session id.
Testet on:
* PHP 7.1.11 on Ubuntu 12.04 (installed via phpbrew)
* PHP 7.0.22-0ubuntu0.16.04.1 on Linux Mint 18
Test script:
---------------
First, create sessiontest.php:
<?php
session_start();
if (!isset($_SESSION['SessionInitiated'])) {
session_regenerate_id();
$_SESSION['SessionInitiated'] = true;
}
?>
Then, access sessiontest.php through Apache and inspect response headers, e.g. by using curl:
curl -sv http://localhost/sessiontest.php >
/dev/null
* Trying 127.0.1.1...
* Connected to localhost (127.0.1.1) port 80 (#0)
> GET /sessiontest.php HTTP/1.1
> Host: localhost
> User-Agent: curl/7.47.0
> Accept: */*
>
< HTTP/1.1 200 OK
< Date: Wed, 22 Nov 2017 12:07:52 GMT
< Server: Apache/2.4.18 (Ubuntu)
< Set-Cookie: PHPSESSID=8676mem4p76uka76ta2qq072q1; path=/
< Expires: Thu, 19 Nov 1981 08:52:00 GMT
< Cache-Control: no-store, no-cache, must-revalidate
< Pragma: no-cache
< Set-Cookie: PHPSESSID=rvud0d79be3oa77rnbag0lmgc2; path=/
< Content-Length: 0
< Content-Type: text/html; charset=UTF-8
Expected result:
----------------
Only send one Set-Cookie header (containing the new session id).
Actual result:
--------------
Two Set-Cookie headers are sent, one containing the old session id and the other containing the new
session id. This confuses browsers and cause some browsers to continue using the old session cookie.
In addition, if you call var_dump(headers_list()) at the end of the script, only ONE Set-Cookie
header will be listed here, even though two headers are sent.
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=75554&edit=1