Bug #80774 [Ver->Csd]: session_name() problem with backslash

From: Date: Mon, 22 Feb 2021 11:38:07 +0000
Subject: Bug #80774 [Ver->Csd]: session_name() problem with backslash
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-232317@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=80774&edit=1 ID: 80774 Updated by: cmb@php.net Reported by: chirpinternet at gmail dot com Summary: session_name() problem with backslash -Status: Verified +Status: Closed Type: Bug Package: Session related Operating System: Debian PHP Version: 7.3.27 Assigned To: cmb Block user comment: N Private report: N New Comment: Automatic comment on behalf of cmbecker69@gmx.de Revision: http://git.php.net/?p=php-src.git;a=commit;h=d7c98ca1ac10ee0461f332f21e548649dc0e51c9 Log: Fix #80774: session_name() problem with backslash Previous Comments: ------------------------------------------------------------------------ [2021-02-19 12:25:27] cmb@php.net The following pull request has been associated: Patch Name: Fix #80774: session_name() problem with backslash On GitHub: https://github.com/php/php-src/pull/6711 Patch: https://github.com/php/php-src/pull/6711.patch ------------------------------------------------------------------------ [2021-02-19 11:13:18] cmb@php.net Thanks for reporting! This regression has been introduced by the fix for bug #79699, because cookie names are no longer URL decoded, but session_name() still URL encodes the session name. Note that PHP 7.3 is out of active support, so this will not be fixed for that version. ------------------------------------------------------------------------ [2021-02-19 09:04:47] chirpinternet at gmail dot com Description: ------------ We have a trait for handling sessions, which includes (abbreviated): trait SessionOpenCloseTrait { protected function open_session($name) { session_name($name); session_start(); } } Other classes invoke this using __CLASS__ as the $name parameter: class SecureToken { use SessionOpenCloseTrait; public function __construct() { $this->open_session(__CLASS__); } } When namespaced, __CLASS__ contains a backslash (e.g. "Parent\SecureToken"). This has not been a problem until a security upgrade took us from 7.3.19 to 7.3.27. After the upgrade the SESSION was being written to the server as normal, but no longer accessible on subsequent requests. *Possibly* due to encoding of the cookie name. To fix this, we had to remove the '\': protected function open_session($name) { + $name = str_replace("\\", "", $name); session_name($name); session_start(); } ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=80774&edit=1

« previous php.bugs (#232317) next »