Bug #77330 [Asn->Fbk]: session_id() no longer works inside custom SessionHandlerInterface

From: Date: Thu, 17 Jan 2019 10:38:31 +0000
Subject: Bug #77330 [Asn->Fbk]: session_id() no longer works inside custom SessionHandlerInterface
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-219031@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=77330&edit=1 ID: 77330 Updated by: yohgaki@php.net Reported by: e6990620 at gmail dot com Summary: session_id() no longer works inside custom SessionHandlerInterface -Status: Assigned +Status: Feedback Type: Bug Package: Session related Operating System: Linux PHP Version: 7.3.0 Assigned To: yohgaki Block user comment: N Private report: N New Comment: ext/session/tests/session_basic2.phpt is not failing, so reporter's 7.3 is not enabling session.strict_mode. To reporter, please verify. Previous Comments: ------------------------------------------------------------------------ [2019-01-17 10:26:10] yohgaki@php.net Reporter, as documented in UPGRADING, PHP 7.3 has more precise session module state management. Older session allowed abuses that can harm session and session module. PHP 7.3 disallowed these harmful/broken usages. i.e. Any changes that can cause "side effect" are disallowed. This code is trying to change active session state. https://3v4l.org/6S4XM Therefore, the code wouldn't work even with ob_start(). Session module was made to work even with harmful/broken usages, and it caused number of bad bugs in the past. public function read($session_id) { // Simulate a session ID regeneration. \session_id('newsessionid'); return ''; } This code is bad code because it is calling session_id() to set "new" id. Setting new ID in user script for active sessions is bad because it has "side effect" to session module internal. The "side effect" can break session. Detailed description is omitted. Anyway, the code is broken. User cannot make any changes that can cause "side effect". I'll check see if strict_mode is broken or not, since reporter claims that 7.3 allows session fixation. ------------------------------------------------------------------------ [2019-01-17 10:16:27] e6990620 at gmail dot com I can confirm that the session.use_strict_mode directive is disabled in all PHP versions (though "strict mode" is actually enforced by the DemoBugSessionHandler code itself). To verify this I just appended this line at the end of the test script in 3v4l: echo ini_get('session.use_strict_mode') . PHP_EOL; and reran. ------------------------------------------------------------------------ [2019-01-17 10:08:44] yohgaki@php.net Ok thanks. I'll have a look to see what is going on. ------------------------------------------------------------------------ [2019-01-17 10:04:53] nikic@php.net @yohgaki: I'm not sure I see what strict mode has to do with this. This change has been introduced in https://github.com/php/php-src/pull/2406. It's a new check, independent of strict mode. ------------------------------------------------------------------------ [2019-01-17 10:01:34] yohgaki@php.net Unless someone changed code and test, there is strict_mode phpt so I suppose stict_mode is not broken. Reporter, please verify. ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=77330 -- Edit this bug report at https://bugs.php.net/bug.php?id=77330&edit=1

« previous php.bugs (#219031) next »