Req #77251 [Com]: Automatically extend PHP session cookie on each request
| From: | spam2 at rhsoft dot net | Date: | Thu, 06 Dec 2018 15:01:45 +0000 |
| Subject: | Req #77251 [Com]: Automatically extend PHP session cookie on each request | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-218291@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=77251&edit=1
ID: 77251
Comment by: spam2 at rhsoft dot net
Reported by: mumu at seznam dot cz
Summary: Automatically extend PHP session cookie on each
request
Status: Open
Type: Feature/Change Request
Package: Session related
Operating System: N/A
PHP Version: 7.2.12
Block user comment: N
Private report: N
New Comment:
session cookies have no cookie expiration - the definition of a session cookie is that it it has a
TLL of 0 which makes it to a session cookie meaning it's gone when you close the browser
Previous Comments:
------------------------------------------------------------------------
[2018-12-06 13:26:04] mumu at seznam dot cz
Description:
------------
The built-in PHP session logic sents a cookie containing a session id when the session_start() call
generates a new session id. The cookie's expiration date is set based on the cookie_lifetime
setting.
However, the cookie is not resent on subsequent requests so its expiration date is never updated
which causes that the cookie might expire before the session expiration.
The PHP sessions have two distinct timeouts:
- cookie expiration - when the browser forgets the cookie containing the session id
- session expiration - when the server forgets the session data
Example:
- The PHP session and cookie life is set to 5 time points
- A user interacts with the site at time points 1, 2 and 4. After each interaction, the expirations
are as follows:
timepoint / PHP session expiration / cookie expiration
1 / 6 / 6
2 / 7 / 6
4 / 9 / 6
- If the sure then interacts with the site at time point 7, the cookie is already expired so it will
not be sent to the server. As such, the request will behave like the PHP session has expired even
the PHP session is technically valid.
To make the PHP sessions useful for this scenario, I suggest that the PHP will send the session
cookie on each request so the cookie's expiration time is properly kept up to date.
Expected result:
----------------
The cookie expiration date is kept up to date so it is always cookie_lifetime after the respective
session was last accessed.
Actual result:
--------------
The cookie expiration date is frozen on to be a cookie_lifetime after the respective session was
created.
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=77251&edit=1