Bug #73529 [Asn->Csd]: session_decode() silently fails on wrong input
Edit report at https://bugs.php.net/bug.php?id=73529&edit=1
ID: 73529
Updated by: cmb@php.net
Reported by: love at sickpeople dot se
Summary: session_decode() silently fails on wrong input
-Status: Assigned
+Status: Closed
Type: Bug
Package: Session related
PHP Version: 7.1.0RC6
Assigned To: yohgaki
Block user comment: N
Private report: N
New Comment:
Automatic comment on behalf of cmbecker69@gmx.de
Revision: http://git.php.net/?p=php-src.git;a=commit;h=08858e7cca223f298e169ed275691769483b2064
Log: Fix #73529: session_decode() silently fails on wrong input
Previous Comments:
------------------------------------------------------------------------
[2020-06-10 10:05:25] cmb@php.net
The following pull request has been associated:
Patch Name: Fix #73529: session_decode() silently fails on wrong input
On GitHub: https://github.com/php/php-src/pull/5698
Patch: https://github.com/php/php-src/pull/5698.patch
------------------------------------------------------------------------
[2016-11-15 14:55:30] love at sickpeople dot se
Description:
------------
The session_decode() returns true on most invalid values. Eg NULL, ints, strings in wrong format and
empty strings.
The docs state "Returns TRUE on success or FALSE on failure." and invalid input should be
considered an error.
..
An important aspect of this is passing data serialized with another method than the current
"session.serialize_handler". These should be considered an error as well. I think this is
implied by the docs:
"By default, the unserialization method used is internal to PHP, and is not the same as
unserialize(). The serialization method can be set using session.serialize_handler."
The following two test scripts shows that setting A as serialize handler and passing input
serialized with B leads to a silent error. The $_SESSION is not populated but true is returned.
Eg
/* Test 1 */
$data = array ('foo' => 'bar');
ini_set ('session.serialize_handler', 'php');
session_start ();
var_dump (session_decode (serialize ($data)));
var_dump ($_SESSION);
/* Test 2 */
ini_set ('session.serialize_handler', 'php_serialize');
session_start ();
var_dump (session_decode ('foo|s:3:"bar";'));
var_dump ($_SESSION);
Test script:
---------------
ini_set ('session.serialize_handler', 'php');
session_start ();
var_dump (session_decode ("foo"));
Expected result:
----------------
session_decode() to return false.
Actual result:
--------------
session_decode() returns true.
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=73529&edit=1
Thread (3 messages)