Bug #77330 [Asn]: session_id() no longer works inside custom SessionHandlerInterface

From: Date: Thu, 17 Jan 2019 10:01:35 +0000
Subject: Bug #77330 [Asn]: session_id() no longer works inside custom SessionHandlerInterface
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-219026@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=77330&edit=1

 ID:                 77330
 Updated by:         yohgaki@php.net
 Reported by:        e6990620 at gmail dot com
 Summary:            session_id() no longer works inside custom
                     SessionHandlerInterface
 Status:             Assigned
 Type:               Bug
 Package:            Session related
 Operating System:   Linux
 PHP Version:        7.3.0
 Assigned To:        yohgaki
 Block user comment: N
 Private report:     N

 New Comment:

Unless someone changed code and test, there is strict_mode phpt so I suppose stict_mode is not
broken. Reporter, please verify.


Previous Comments:
------------------------------------------------------------------------
[2019-01-17 09:53:09] yohgaki@php.net

While I've been proposed enabling stricrt_mode by default, but it's not enabled yet.
Current implementation requires 2 session data read when strict mode is enabled, but this can be
save to 1 read. 

This is rather simple change, but it requires save handler API change.

------------------------------------------------------------------------
[2019-01-17 09:50:23] yohgaki@php.net

Your PHP 7.2 is enabling session.strict_mode=On while 7.3 is not.

------------------------------------------------------------------------
[2019-01-02 09:09:59] nikic@php.net

Maybe we should revert this change for now? Until someone with good ext/session understanding can
look at this, I think it's okay to just drop the warning in the meantime.

------------------------------------------------------------------------
[2018-12-21 15:05:36] cmb@php.net

This behavioral change has been introduced by merging pull request
2406[1].  Yasuo, can you please have a look at this?  There will
also be a warning, if the session ID is changed in
SessionHandlerInterface::open().

[1] <https://github.com/php/php-src/pull/2406>

------------------------------------------------------------------------
[2018-12-20 21:10:38] e6990620 at gmail dot com

Description:
------------
Up until PHP 7.3.0 when you wrote a custom SessionHandlerInterface you could signal the PHP engine
to regenerate the ID by calling session_id('newvalue') inside its read() method. Then,
when the session closed and the engine calls the write() method, $session_id used to be the new
value.

Starting from PHP 7.3.0 this pattern no longer works, as write() receives the stale value.

Might be related to https://bugs.php.net/bug.php?id=74941 since it is
the only session-related change in this new major release.

Another bug report of the same issue in a real world session handler: https://github.com/1ma/RedisSessionHandler/issues/11

Test script:
---------------
https://3v4l.org/6S4XM

Expected result:
----------------
$ curl -i -H "Cookie: PHPSESSID=madeupkey;" localhost/bug.php;

HTTP/1.1 200 OK
Server: nginx/1.13.12
Date: Thu, 20 Dec 2018 20:51:23 GMT
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: keep-alive
X-Powered-By: PHP/7.2.13                 <------------ PHP 7.2
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate
Pragma: no-cache

newsessionid

Actual result:
--------------
$ curl -i -H "Cookie: PHPSESSID=madeupkey;" localhost/bug.php;

HTTP/1.1 200 OK
Server: nginx/1.13.12
Date: Thu, 20 Dec 2018 20:51:25 GMT
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: keep-alive
X-Powered-By: PHP/7.3.0                  <------------ PHP 7.3
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate
Pragma: no-cache

madeupkey        <------ successful session fixation attack


------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=77330&edit=1


Thread (15 messages)

« previous php.bugs (#219026) next »