Req #65746 [Com]: session_regenerate_id() should not delete old session data immediately.

From: Date: Thu, 31 May 2018 09:01:42 +0000
Subject: Req #65746 [Com]: session_regenerate_id() should not delete old session data immediately.
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-215449@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=65746&edit=1

 ID:                 65746
 Comment by:         tony at marston-home dot demon dot co dot uk
 Reported by:        yohgaki@php.net
 Summary:            session_regenerate_id() should not delete old
                     session data immediately.
 Status:             Assigned
 Type:               Feature/Change Request
 Package:            Session related
 PHP Version:        5.5Git-2013-09-23 (Git)
 Assigned To:        yohgaki
 Block user comment: N
 Private report:     N

 New Comment:

session_regenerate_id() was never meant to destroy the session data, that is what unset($_SESSION)
is for. Not even session_destroy() will delete the $_SESSION array, which means that it can be
reused with the next call to session_start().

It is perfectly legitimate to open a session with one id, thus obtaining the $_SESSION array, then
to use session_regenerate_id() to change the session_id() so that it can be saved under the new id.
Any scripts still using the previous session_id() will still work. While both sessions start off
with copies of the same $_SESSION array, these copies can quickly diverge because they are different
copies being accessed with different ids.


Previous Comments:
------------------------------------------------------------------------
[2016-10-17 06:38:05] yohgaki@php.net

Use proper title. Original title meant "no deletion by __default__".
Last RFC is declined, but we _MUST_ fix this issue.

session_regenerate_id() depreciation is a option. We shouldn't keep security related broken
function.

------------------------------------------------------------------------
[2015-09-29 02:07:59] yohgaki@php.net

Related RFC
https://wiki.php.net/rfc/precise_session_management

------------------------------------------------------------------------
[2015-07-11 20:45:00] ab@php.net

Related To: Bug #70013

------------------------------------------------------------------------
[2015-05-24 06:21:56] yohgaki@php.net

Patch was there, but there are some objections for lazy destroy. I think there is no objection now.

This bug is related to 
https://bugs.php.net/bug.php?id=69127

------------------------------------------------------------------------
[2014-03-12 11:44:18] narf at devilix dot net

Huh, well ... it was last discussed 4 months ago and the RFC hasn't been updated since.

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=65746


--
Edit this bug report at https://bugs.php.net/bug.php?id=65746&edit=1


Thread (20 messages)

« previous php.bugs (#215449) next »