Bug #77330 [Asn]: session_id() no longer works inside custom SessionHandlerInterface

From: Date: Thu, 17 Jan 2019 09:50:24 +0000
Subject: Bug #77330 [Asn]: session_id() no longer works inside custom SessionHandlerInterface
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-219024@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=77330&edit=1 ID: 77330 Updated by: yohgaki@php.net Reported by: e6990620 at gmail dot com Summary: session_id() no longer works inside custom SessionHandlerInterface Status: Assigned Type: Bug Package: Session related Operating System: Linux PHP Version: 7.3.0 Assigned To: yohgaki Block user comment: N Private report: N New Comment: Your PHP 7.2 is enabling session.strict_mode=On while 7.3 is not. Previous Comments: ------------------------------------------------------------------------ [2019-01-02 09:09:59] nikic@php.net Maybe we should revert this change for now? Until someone with good ext/session understanding can look at this, I think it's okay to just drop the warning in the meantime. ------------------------------------------------------------------------ [2018-12-21 15:05:36] cmb@php.net This behavioral change has been introduced by merging pull request 2406[1]. Yasuo, can you please have a look at this? There will also be a warning, if the session ID is changed in SessionHandlerInterface::open(). [1] <https://github.com/php/php-src/pull/2406> ------------------------------------------------------------------------ [2018-12-20 21:10:38] e6990620 at gmail dot com Description: ------------ Up until PHP 7.3.0 when you wrote a custom SessionHandlerInterface you could signal the PHP engine to regenerate the ID by calling session_id('newvalue') inside its read() method. Then, when the session closed and the engine calls the write() method, $session_id used to be the new value. Starting from PHP 7.3.0 this pattern no longer works, as write() receives the stale value. Might be related to https://bugs.php.net/bug.php?id=74941 since it is the only session-related change in this new major release. Another bug report of the same issue in a real world session handler: https://github.com/1ma/RedisSessionHandler/issues/11 Test script: --------------- https://3v4l.org/6S4XM Expected result: ---------------- $ curl -i -H "Cookie: PHPSESSID=madeupkey;" localhost/bug.php; HTTP/1.1 200 OK Server: nginx/1.13.12 Date: Thu, 20 Dec 2018 20:51:23 GMT Content-Type: text/html; charset=UTF-8 Transfer-Encoding: chunked Connection: keep-alive X-Powered-By: PHP/7.2.13 <------------ PHP 7.2 Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate Pragma: no-cache newsessionid Actual result: -------------- $ curl -i -H "Cookie: PHPSESSID=madeupkey;" localhost/bug.php; HTTP/1.1 200 OK Server: nginx/1.13.12 Date: Thu, 20 Dec 2018 20:51:25 GMT Content-Type: text/html; charset=UTF-8 Transfer-Encoding: chunked Connection: keep-alive X-Powered-By: PHP/7.3.0 <------------ PHP 7.3 Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate Pragma: no-cache madeupkey <------ successful session fixation attack ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=77330&edit=1

« previous php.bugs (#219024) next »