Bug #77238 [Nab]: session_set_cookie_params behavior change in PHP 7.2

From: Date: Sat, 08 Dec 2018 06:26:41 +0000
Subject: Bug #77238 [Nab]: session_set_cookie_params behavior change in PHP 7.2
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-218330@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=77238&edit=1 ID: 77238 Updated by: yohgaki@php.net Reported by: john at zerocrates dot org Summary: session_set_cookie_params behavior change in PHP 7.2 Status: Not a bug Type: Bug Package: Session related Operating System: Linux PHP Version: 7.2.12 Block user comment: N Private report: N New Comment: Please refer to PHP 7.2's UPGRADING in the source. Changning session parameter for active session was the main cause of the session related bugs. Previous Comments: ------------------------------------------------------------------------ [2018-12-08 06:21:20] yohgaki@php.net Program must set all parameters for session before activating session from PHP 7.2. ------------------------------------------------------------------------ [2018-12-04 19:12:02] john at zerocrates dot org Bug #76358 seems to be a different facet of the same basic problem or change. ------------------------------------------------------------------------ [2018-12-04 18:58:22] john at zerocrates dot org Description: ------------ Under PHP 7.1, calling session_set_cookie_params with an active session will successfully change the cookie sent to the client, IF session_regenerate_id is called afterward. In PHP 7.2, calling session_set_cookie_params with an active session emits a warning: Warning: session_set_cookie_params(): Cannot change session cookie parameters when session is active Additionally, the cookie is _not_ changed. I've seen this described as a change which merely emits warnings informing developers of patterns that never worked in the first place and just failed silently (for example, the comments on #75650), but in this case presumably the function is bailing out after printing the warning, and the actual behavior is changed. I was unable to find any discussion of this change in the migration documentation for PHP 7.2. Test script: --------------- session_start(); $params = session_get_cookie_params(); session_set_cookie_params(100, $params['path'], $params['domain'], $params['secure']); session_regenerate_id(); // Under 7.1 this emits a Set-Cookie with the 100-second lifetime respected // Under 7.2, it produces a warning and the Set-Cookie does not respect the new lifetime ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=77238&edit=1

« previous php.bugs (#218330) next »