Bug #76358 [Nab]: Cannot change session name when session is active

From: Date: Sun, 20 May 2018 19:57:39 +0000
Subject: Bug #76358 [Nab]: Cannot change session name when session is active
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-215307@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=76358&edit=1

 ID:                 76358
 User updated by:    tony at marston-home dot demon dot co dot uk
 Reported by:        tony at marston-home dot demon dot co dot uk
 Summary:            Cannot change session name when session is active
 Status:             Not a bug
 Type:               Bug
 Package:            Session related
 Operating System:   Windows 10
 PHP Version:        7.2.5
 Block user comment: N
 Private report:     N

 New Comment:

I already use session_name() to provide the name of the new session before I start that session with
session_start(). The problem is that the function no longer works as AS ADVERTISED as it can no
longer return the name of the existing session before it starts the new one.

This function has worked AS ADVERISED for over 15 years, so why was it changed? For what problem is
this change in behaviour supposed to be a solution?


Previous Comments:
------------------------------------------------------------------------
[2018-05-20 18:33:29] peehaa@php.net

The documentation also clearly states "Thus, you need to call session_name() for every request
(and before session_start() or session_register() are called)."

http://php.net/manual/en/function.session-name.php

------------------------------------------------------------------------
[2018-05-20 17:19:50] tony at marston-home dot demon dot co dot uk

Description:
------------
This error was introduced in 7.2 for no good reason. I have been using this technique since 2003 to
enable a user to have multiple sessions on the same PC, each with its own name and ID. This now
fails.

I know that https://bugs.php.net/bug.php?id=75650 has declared
that this not a bug, but I strongly disagree.

Why was this change made? What was the reasoning? If this usage does not cause a problem in the
engine then why is it now being disallowed? If this is someone's idea of "purity"
then that someone needs a good talking to as this is overstepping the mark.


Test script:
---------------
session_start();
$old_name = session_name('NEWSESSION');  // with 7.2 this now returns FALSE
session_regenerate_id();
… do something
session_name($old_name);  // with 7.2 this now fails as $old_name is FALSE

Expected result:
----------------
I expect session_name() to do what it has been doing for the past 15 years, that is to return the
existing session name while assigning a new one. The documentation clearly states "Get and/or
set the current session name", and the "and/or" indicates that it should be able to
do both at the same time.

Actual result:
--------------
session_name() returns FALSE instead of the current session name.


------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=76358&edit=1


Thread (15 messages)

« previous php.bugs (#215307) next »