Bug #77251 [Asn]: Automatically extend PHP session cookie on each request

From: Date: Fri, 10 Sep 2021 15:50:35 +0000
Subject: Bug #77251 [Asn]: Automatically extend PHP session cookie on each request
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-236526@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=77251&edit=1 ID: 77251 Updated by: cmb@php.net Reported by: mumu at seznam dot cz Summary: Automatically extend PHP session cookie on each request Status: Assigned Type: Bug Package: Session related Operating System: N/A PHP Version: 7.2.12 Assigned To: yohgaki Block user comment: N Private report: N New Comment: > For example, the user logs in into the web site and closes the > browser. After the user reopens the browser again soon enough, the > user will be still logged into the website. And if another users opens the browser again, they are logged in as well. In my opinion, this is never desireable. I'd rather deprecate session.cookie_lifetime. Previous Comments: ------------------------------------------------------------------------ [2020-06-16 11:01:08] php dot net at itsacon dot net As of June 2020, this bug still exists. It basically means that if, for security reasons, you limit the lifetime of the session cookie, you automatically limit the lifetime of your sessions as well, regardless of user activity. We have a script that sends keepalives every 10 seconds, and it still gets kicked out after the session cookie expires. The only workaround I've found is calling session_regenerate_id() on every call, but that has its own set of side-effects. It would be nice if responses would automatically send an updated cookie along, so any server call would reset the lifetime. If that's not possible, a session_refresh_cookie() function might be an acceptable solution. ------------------------------------------------------------------------ [2018-12-08 07:13:50] yohgaki@php.net Although session.c calls php_session_reset_id() within php_session_initialize(), it does not send session cookie header because PS(send_cookie) flag is 0 when session cookie is present. ------------------------------------------------------------------------ [2018-12-06 15:10:39] spam2 at rhsoft dot net then code it yourself with your own cookie as everybody out here does in combination with "remember login" checkboxes leading to trigger a re-login but don't try to absue SESSION COOKIES for what they are not ------------------------------------------------------------------------ [2018-12-06 15:07:37] mumu at seznam dot cz That's a definition for a 'session cookie' from a browser point of view, not from a PHP point of view. I would like the PHP session to be kept alive even when the browser is closed and than reopened. For example, the user logs in into the web site and closes the browser. After the user reopens the browser again soon enough, the user will be still logged into the website. ------------------------------------------------------------------------ [2018-12-06 15:01:45] spam2 at rhsoft dot net session cookies have no cookie expiration - the definition of a session cookie is that it it has a TLL of 0 which makes it to a session cookie meaning it's gone when you close the browser ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=77251 -- Edit this bug report at https://bugs.php.net/bug.php?id=77251&edit=1

« previous php.bugs (#236526) next »