Bug #80774 [PATCH]: session_name() problem with backslash
| From: | cmb@php.net | Date: | Fri, 19 Feb 2021 12:25:27 +0000 |
| Subject: | Bug #80774 [PATCH]: session_name() problem with backslash | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-232280@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=80774&edit=1
ID: 80774
Patch added by: cmb@php.net
Reported by: chirpinternet at gmail dot com
Summary: session_name() problem with backslash
Status: Verified
Type: Bug
Package: Session related
Operating System: Debian
PHP Version: 7.3.27
Assigned To: cmb
Block user comment: N
Private report: N
New Comment:
The following pull request has been associated:
Patch Name: Fix #80774: session_name() problem with backslash
On GitHub: https://github.com/php/php-src/pull/6711
Patch: https://github.com/php/php-src/pull/6711.patch
Previous Comments:
------------------------------------------------------------------------
[2021-02-19 11:13:18] cmb@php.net
Thanks for reporting!
This regression has been introduced by the fix for bug #79699,
because cookie names are no longer URL decoded, but session_name()
still URL encodes the session name.
Note that PHP 7.3 is out of active support, so this will not be
fixed for that version.
------------------------------------------------------------------------
[2021-02-19 09:04:47] chirpinternet at gmail dot com
Description:
------------
We have a trait for handling sessions, which includes (abbreviated):
trait SessionOpenCloseTrait {
protected function open_session($name) {
session_name($name);
session_start();
}
}
Other classes invoke this using __CLASS__ as the $name parameter:
class SecureToken {
use SessionOpenCloseTrait;
public function __construct() {
$this->open_session(__CLASS__);
}
}
When namespaced, __CLASS__ contains a backslash (e.g. "Parent\SecureToken"). This has not
been a problem until a security upgrade took us from 7.3.19 to 7.3.27. After the upgrade the
SESSION was being written to the server as normal, but no longer accessible on subsequent requests.
*Possibly* due to encoding of the cookie name.
To fix this, we had to remove the '\':
protected function open_session($name) {
+ $name = str_replace("\\", "", $name);
session_name($name);
session_start();
}
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=80774&edit=1