Req #72091 [Opn->Wfx]: session data persistence after destroying session
| From: | cmb@php.net | Date: | Wed, 09 Dec 2020 17:49:56 +0000 |
| Subject: | Req #72091 [Opn->Wfx]: session data persistence after destroying session | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-230976@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=72091&edit=1
ID: 72091
Updated by: cmb@php.net
Reported by: rprporwal9 at gmail dot com
Summary: session data persistence after destroying session
-Status: Open
+Status: Wont fix
Type: Feature/Change Request
Package: Session related
Operating System: Ubuntu
PHP Version: 5.5.34
-Assigned To:
+Assigned To: cmb
Block user comment: N
Private report: N
New Comment:
function my_special_session_destroy() {
session_destroy();
unset($_SESSION);
}
Since this can easily be implemented in userland, but changing the
behavior of session_destroy() would introduce a BC break, I see no
point in this feature. If you feel stronly that this would be an
improvement, please forward the feature request to the internals
mailing list.
Previous Comments:
------------------------------------------------------------------------
[2016-04-24 18:18:24] stas@php.net
Not a security issue.
Also, documented behavior of session_destroy.
------------------------------------------------------------------------
[2016-04-24 05:21:09] rprporwal9 at gmail dot com
Description:
------------
After session initialization we store data in session super global array but after invocation of
session_destroy function which is used to destroy session data in session super global variable
should also be unset simultaneously.
Otherwise there is no meaning of session_destroy if data persists in session super global variable
Also according to documentation of session_destroy function as mentioned in php.net
Destroys all data registered to a session
Hence I suggest that data should not persist after session is destroyed in super global $_SESSION
variable otherwise there is no reliability of session_destroy() function.
Test script:
---------------
session_start();
$_SESSION['xyz']=99;
session_destroy();
print_r($_SESSION);
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=72091&edit=1