Bug #77384 [Com]: Unable to change Session Save Handler to "user"

From: Date: Fri, 04 Jan 2019 12:58:53 +0000
Subject: Bug #77384 [Com]: Unable to change Session Save Handler to "user"
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-218793@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=77384&edit=1 ID: 77384 Comment by: info at dreamtimeshop dot com Reported by: info at dreamtimeshop dot com Summary: Unable to change Session Save Handler to "user" Status: Feedback Type: Bug Package: Session related Operating System: Windows, Linux PHP Version: 7.2.0 Block user comment: N Private report: N New Comment: oops... sorry, I am still a bit confused after the long holidays :-) ... The docu page is http://php.net/manual/en/function.session-module-name.php and there is not much in it. After all it says, it can "Get and/or set the current session module", and obviously nothing has changed since a long time, I tried to set ("as always"), and got those error messages. Previous Comments: ------------------------------------------------------------------------ [2019-01-04 12:43:27] info at dreamtimeshop dot com Hello and thank you. Surprisingly, you are right! My complete code was as follows: public static function _init() { session_module_name('user'); session_set_save_handler( array('ADODB_Session', 'sess_open'), array('ADODB_Session', 'sess_close'), array('ADODB_Session', 'sess_read'), array('ADODB_Session', 'sess_write'), array('ADODB_Session', 'sess_destroy'), array('ADODB_Session', 'sess_gc') ); register_shutdown_function('session_write_close'); } It worked fine in all PHP versions, except when trying to upgrade to 7.2 or 7.3. After your comment, I commented out the line "session_module_name('user');", and it works indeed! Surely it makes no sense to call session_module_name exclusively without doing anything further. Until now, this was always done just before calling "session_set_save_handler". The current PHP documentation even indirectly mentions this as a prerequisite for using the database for sessions. Quote: session_set_save_handler() sets the user-level session storage functions which are used for storing and retrieving data associated with a session. This is most useful when a storage method other than those supplied by PHP sessions is preferred, e.g. storing the session data in a local database. ( http://php.net/manual/en/function.session-set-save-handler.php ) According to this doc page, nothing has changed since version 7.0. If it is not a bug, then this is a clear error in the documentation! Because in versions 7.2 and 7.3 "session_module_name" must not be used if you want to save sessions in the database. ------------------------------------------------------------------------ [2019-01-04 12:18:02] nikic@php.net Yes, the exact version here is not really important, just that this was first introduced in 7.2. But ... I don't really get what this bug is about. I'm not a session expert, but isn't the "user" save handler set by calling session_set_save_handler()? What would it even mean to use the "user" handler without calling session_set_save_handler()? I expect that this was an intentional change to prevent exactly this kind of code. ------------------------------------------------------------------------ [2019-01-04 12:06:51] info at dreamtimeshop dot com It affects both newest PHP 7.2 (7.2.13) and 7.3 (7.3.0). Not only "7.2.0"! Exactly same code works flawlessly under PHP 7.1.25 and older. ------------------------------------------------------------------------ [2018-12-30 23:31:04] info at dreamtimeshop dot com Description: ------------ In the PHP 7.2 and 7.3, there is not possible to set "user" as Session Save Handler. 1) unable to set it in php.ini: The php.ini file includes line "session.save_handler = user". phpinfo() says: "Registered save handlers: files user" but below always shows "files" as current handler. 2) unable to change it in the scripts: None ot those two pssibilities work: session_module_name('user'); ini_set('session.save_handler', 'user'); Both of them throw a "Recoverable fatal error" which says "Cannot set 'user' save handler by ini_set() or session_module_name()"... Tested on CentOS and Windows 10 with PHP 7.2.13 and PHP 7.3.0. Older versions incl. PHP 7.1.15 are working as expected. Test script: --------------- <?php session_module_name('user'); ini_set('session.save_handler', 'user'); ?> Expected result: ---------------- (nothing) Actual result: -------------- Recoverable fatal error: session_module_name(): Cannot set 'user' save handler by ini_set() or session_module_name() in ... ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=77384&edit=1

« previous php.bugs (#218793) next »