Req #78054 [Opn]: session_decode should optionally return data rather than populate $_SESSION
| From: | phpbugs dot ooglek at 0sg dot net | Date: | Thu, 23 May 2019 04:09:55 +0000 |
| Subject: | Req #78054 [Opn]: session_decode should optionally return data rather than populate $_SESSION | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-220956@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=78054&edit=1
ID: 78054
User updated by: phpbugs dot ooglek at 0sg dot net
Reported by: phpbugs dot ooglek at 0sg dot net
Summary: session_decode should optionally return data rather
than populate $_SESSION
Status: Open
Type: Feature/Change Request
Package: Session related
PHP Version: 7.3.5
Block user comment: N
Private report: N
New Comment:
The three supported options for session.serialize_handler are
php
php_binary
php_serialize (5.5.4+ only)
If someone writes their own handler, they now have to expose some method for someone else to decode
their serialized session data.
session_decode() already knows how to handle this, no special case handling necessary.
Previous Comments:
------------------------------------------------------------------------
[2019-05-23 04:07:36] phpbugs dot ooglek at 0sg dot net
Description:
------------
Storing sessions in a Database is great for high-availability and sharing sessions across multiple
web hosts.
However, when one wants to deeply inspect the session data, such as an administrator or an Admin
Tool that displays all the information about a current session, there seems to be two options.
1. For a short time, hijack $_SESSION
$tmp = session_encode();
session_decode($data);
$sessdata = $_SESSION;
session_decode($tmp);
This replaces the current users' $_SESSION with the decoded data until one has time to restore
it. If it doesn't restore successfully, you've got a bad situation.
2. Write your own unserialize functions. Wikimedia had to. Yuck. ADODB had one that
preg_match'd on a Pipe character, but that broke if the value contained pipes. Someone else
wrote a recursive one that worked pretty well and took advantage of the fact that unserialize() will
stop unserializing at the next pipe in the string. OK but is that guaranteed to keep working
forever?
If session_decode() would be able to return the decoded session (FALSE on failure as it does now,
but success gives you the array/object), then nobody would have to write or maintain code that may
or may not be exactly how session_decode() works.
Additionally if people start writing their own handlers, yikes.
session_decode_return() or something similar would be fine too if you don't want to overload
session_decode().
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=78054&edit=1