Bug #74548 [Com]: Session name and session id binding
| From: | tony at marston-home dot demon dot co dot uk | Date: | Wed, 30 May 2018 10:16:49 +0000 |
| Subject: | Bug #74548 [Com]: Session name and session id binding | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-215427@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=74548&edit=1
ID: 74548
Comment by: tony at marston-home dot demon dot co dot uk
Reported by: gollumben at gmx dot de
Summary: Session name and session id binding
Status: Open
Type: Bug
Package: Session related
Operating System: Debian GNU/Linux 8 (jessie)
PHP Version: 7.0.18
Block user comment: N
Private report: N
New Comment:
This is not a bug.
The session name and id are different entities which can be changed independently of each other.
Changing one does not automatically change the other. If you want to change the name then use
session_name(). If you want to change the id then use session_regenerate_id(). The correct code to
do what you want is as follows:
session_start(); // obtains $_SESSION array
⦠do stuff
session_name('newname'); // change session name only
session_regenerate_id(); // change session id only
session_write_close(); // required otherwise the next call will to
// session_start() will fail
session_start(); // starts session with new name and id and
// old $_SESSION array
Previous Comments:
------------------------------------------------------------------------
[2017-05-06 09:46:31] gollumben at gmx dot de
Description:
------------
When starting a session with a certain name, closing it and starting a session with a different
name, the session ID is not changed. I find this misleading. I use cookies for the session ID
storage and with this procedure there will be two cookies with different names with the same session
ID.
In my opinion, PHP should create a new session ID for a new session with a different name. This also
makes makes sense from a different point of view: When starting a session with a different name, PHP
will want to look for the cookie with the other name.
Admitting, the practice of using multiple sessions within one script is not be the best.
Test script:
---------------
session_name("session1");
session_start();
echo session_name() ." ". session_id() ."<br>";
session_write_close();
session_name("session2");
session_start();
echo session_name() ." ". session_id(); //the ID will be the same as before
Expected result:
----------------
The second session ID should be different from the first one.
Actual result:
--------------
The second session ID and the first are the same.
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=74548&edit=1