Req #77251 [NEW]: Automatically extend PHP session cookie on each request
| From: | mumu at seznam dot cz | Date: | Thu, 06 Dec 2018 13:26:04 +0000 |
| Subject: | Req #77251 [NEW]: Automatically extend PHP session cookie on each request | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-218290@lists.php.net to get a copy of this message | ||
From: mumu at seznam dot cz
Operating system: N/A
PHP version: 7.2.12
Package: Session related
Bug Type: Feature/Change Request
Bug description:Automatically extend PHP session cookie on each request
Description:
------------
The built-in PHP session logic sents a cookie containing a session id
when the session_start() call generates a new session id. The cookie's
expiration date is set based on the cookie_lifetime setting.
However, the cookie is not resent on subsequent requests so its
expiration date is never updated which causes that the cookie might
expire before the session expiration.
The PHP sessions have two distinct timeouts:
- cookie expiration - when the browser forgets the cookie containing the
session id
- session expiration - when the server forgets the session data
Example:
- The PHP session and cookie life is set to 5 time points
- A user interacts with the site at time points 1, 2 and 4. After each
interaction, the expirations are as follows:
timepoint / PHP session expiration / cookie expiration
1 / 6 / 6
2 / 7 / 6
4 / 9 / 6
- If the sure then interacts with the site at time point 7, the cookie
is already expired so it will not be sent to the server. As such, the
request will behave like the PHP session has expired even the PHP
session is technically valid.
To make the PHP sessions useful for this scenario, I suggest that the
PHP will send the session cookie on each request so the cookie's
expiration time is properly kept up to date.
Expected result:
----------------
The cookie expiration date is kept up to date so it is always
cookie_lifetime after the respective session was last accessed.
Actual result:
--------------
The cookie expiration date is frozen on to be a cookie_lifetime after
the respective session was created.
--
Edit bug report at https://bugs.php.net/bug.php?id=77251&edit=1
--
Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=77251&r=trysnapshot54
Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=77251&r=trysnapshot55
Try a snapshot (trunk): https://bugs.php.net/fix.php?id=77251&r=trysnapshottrunk
Fixed in SVN: https://bugs.php.net/fix.php?id=77251&r=fixed
Fixed in release: https://bugs.php.net/fix.php?id=77251&r=alreadyfixed
Need backtrace: https://bugs.php.net/fix.php?id=77251&r=needtrace
Need Reproduce Script: https://bugs.php.net/fix.php?id=77251&r=needscript
Try newer version: https://bugs.php.net/fix.php?id=77251&r=oldversion
Not developer issue: https://bugs.php.net/fix.php?id=77251&r=support
Expected behavior: https://bugs.php.net/fix.php?id=77251&r=notwrong
Not enough info: https://bugs.php.net/fix.php?id=77251&r=notenoughinfo
Submitted twice: https://bugs.php.net/fix.php?id=77251&r=submittedtwice
register_globals: https://bugs.php.net/fix.php?id=77251&r=globals
PHP 4 support discontinued: https://bugs.php.net/fix.php?id=77251&r=php4
Daylight Savings: https://bugs.php.net/fix.php?id=77251&r=dst
IIS Stability: https://bugs.php.net/fix.php?id=77251&r=isapi
Install GNU Sed: https://bugs.php.net/fix.php?id=77251&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=77251&r=float
No Zend Extensions: https://bugs.php.net/fix.php?id=77251&r=nozend
MySQL Configuration Error: https://bugs.php.net/fix.php?id=77251&r=mysqlcfg