Bug #78858 [Opn]: session_set_cookie_params() can't be used with php_admin_*

From: Date: Mon, 25 Nov 2019 11:54:37 +0000
Subject: Bug #78858 [Opn]: session_set_cookie_params() can't be used with php_admin_*
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-223881@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=78858&edit=1

 ID:                 78858
 User updated by:    pajomasoma at gmail dot com
 Reported by:        pajomasoma at gmail dot com
 Summary:            session_set_cookie_params() can't be used with
                     php_admin_*
 Status:             Open
 Type:               Bug
 Package:            PHP options/info functions
 Operating System:   Linux
 PHP Version:        7.3.12
 Block user comment: N
 Private report:     N

 New Comment:

Not trying to read the values.

The issue is if one tries to use session_set_cookie_params() when a setting has been locked with
php_admin_*.

For example, it's not possible to change session.httponly using the $httpOnly parameter of
session_set_cookie_params, if session.secure was locked with php_admin_flag — even if the
value on the session_set_cookie_params() call is the same one.


Previous Comments:
------------------------------------------------------------------------
[2019-11-22 17:43:48] fgfgfgfdf at somewhere dot com

just don't use session_set_cookie_params() when you want to read and ther is
session_get_cookie_params()

------------------------------------------------------------------------
[2019-11-22 17:03:28] pajomasoma at gmail dot com

Description:
------------
session_set_cookie_params() fails if one of the setting below has been set by
php_admin_flag/php_admin_value, even if not trying to change them.

session.httponly
session.secure
session.samesite

Not clear if this is intended behavior. I expected to be able to use session_set_cookie_params() if
not trying to change from what was set by php_admin_flag/php_admin_value. Instead, it fails,
ignoring other values that could have been set (see test script for samesite setting example).

Test script:
---------------
// php_admin_flag[session.cookie_httponly] = on
// php_admin_flag[session.cookie_secure] = on 

print_r($cookieParams = session_get_cookie_params());

$cookieParams['samesite'] = 'Lax';
var_dump(session_set_cookie_params($cookieParams));

print_r(session_get_cookie_params());

Expected result:
----------------
Array
(
    [lifetime] => 0
    [path] => /
    [domain] => 
    [secure] => 1
    [httponly] => 1
    [samesite] => 
)
bool(true)
Array
(
    [lifetime] => 0
    [path] => /
    [domain] => 
    [secure] => 1
    [httponly] => 1
    [samesite] => Lax
)

Actual result:
--------------
Array
(
    [lifetime] => 0
    [path] => /
    [domain] => 
    [secure] => 1
    [httponly] => 1
    [samesite] => 
)
bool(false)
Array
(
    [lifetime] => 0
    [path] => /
    [domain] => 
    [secure] => 1
    [httponly] => 1
    [samesite] => 
)


------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=78858&edit=1


Thread (4 messages)

« previous php.bugs (#223881) next »