Bug #78858 [Opn]: session_set_cookie_params() can't be used with php_admin_*

From: Date: Mon, 25 Nov 2019 17:10:54 +0000
Subject: Bug #78858 [Opn]: session_set_cookie_params() can't be used with php_admin_*
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-223889@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=78858&edit=1

 ID:                 78858
 Updated by:         cmb@php.net
 Reported by:        pajomasoma at gmail dot com
 Summary:            session_set_cookie_params() can't be used with
                     php_admin_*
 Status:             Open
 Type:               Bug
 Package:            PHP options/info functions
 Operating System:   Linux
 PHP Version:        7.3.12
 Block user comment: N
 Private report:     N

 New Comment:

session_set_cookie_params() walks through all given options in the
order lifetime, path, domain, secure, httponly and samesite, and
tries to change the ini setting (without checking whether the new
value is different).  On the first failed attempt to do so, the
function returns.

You can just unset those options which are not allowed to be
changed.


Previous Comments:
------------------------------------------------------------------------
[2019-11-25 11:54:37] pajomasoma at gmail dot com

Not trying to read the values.

The issue is if one tries to use session_set_cookie_params() when a setting has been locked with
php_admin_*.

For example, it's not possible to change session.httponly using the $httpOnly parameter of
session_set_cookie_params, if session.secure was locked with php_admin_flag — even if the
value on the session_set_cookie_params() call is the same one.

------------------------------------------------------------------------
[2019-11-22 17:43:48] fgfgfgfdf at somewhere dot com

just don't use session_set_cookie_params() when you want to read and ther is
session_get_cookie_params()

------------------------------------------------------------------------
[2019-11-22 17:03:28] pajomasoma at gmail dot com

Description:
------------
session_set_cookie_params() fails if one of the setting below has been set by
php_admin_flag/php_admin_value, even if not trying to change them.

session.httponly
session.secure
session.samesite

Not clear if this is intended behavior. I expected to be able to use session_set_cookie_params() if
not trying to change from what was set by php_admin_flag/php_admin_value. Instead, it fails,
ignoring other values that could have been set (see test script for samesite setting example).

Test script:
---------------
// php_admin_flag[session.cookie_httponly] = on
// php_admin_flag[session.cookie_secure] = on 

print_r($cookieParams = session_get_cookie_params());

$cookieParams['samesite'] = 'Lax';
var_dump(session_set_cookie_params($cookieParams));

print_r(session_get_cookie_params());

Expected result:
----------------
Array
(
    [lifetime] => 0
    [path] => /
    [domain] => 
    [secure] => 1
    [httponly] => 1
    [samesite] => 
)
bool(true)
Array
(
    [lifetime] => 0
    [path] => /
    [domain] => 
    [secure] => 1
    [httponly] => 1
    [samesite] => Lax
)

Actual result:
--------------
Array
(
    [lifetime] => 0
    [path] => /
    [domain] => 
    [secure] => 1
    [httponly] => 1
    [samesite] => 
)
bool(false)
Array
(
    [lifetime] => 0
    [path] => /
    [domain] => 
    [secure] => 1
    [httponly] => 1
    [samesite] => 
)


------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=78858&edit=1


Thread (4 messages)

« previous php.bugs (#223889) next »