#23689 [Bgs]: serializing - deserializing session data doesn't work

From: Date: Sun, 18 May 2003 23:51:34 +0000
Subject: #23689 [Bgs]: serializing - deserializing session data doesn't work
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-39918@lists.php.net to get a copy of this message
ID: 23689 User updated by: marty at excudo dot net Reported By: marty at excudo dot net Status: Bogus Bug Type: Session related Operating System: linux PHP Version: 4.3.1 New Comment: I'm not sure whether you choose your words badly, or not, but Serializing is not the problem. Serializing the $_SESSION data works fine (as my example shows). The problem is filling $_SESSION again by UNserializing the serialized representation. Also, nowhere in the manual it is pointed out that the (un)serialize function can't be used with these superglobals. (and if this is really true it should do so!!) Is there really a reason why this should not be done / doesn't work, or is it a bug after all and this the answer i get because no one at php is gonna fix it? Ok, sorry, i don't mean to flame, but this is a very unsatisfactory answer - i spent a lot of time on this function and also a lot of time creating a proper bug-report! Just answer this question for me then: If i create 3 temporary arrays, by filling them with the data from $_GET, $_POST and $_SESSION -> i serialize Them and store them in my db. And then when i want to restore them i unset() $_SESSION again (unsetting $_GET and $_POST won't be necessart at this point); i unserialize the data from the database, store them in 3 temporary arrays and then assign those arrays again to $_SESSION, $_GET and $_POST ($_SESSION = $temporary_array;) That should, in theory, work then, right? Previous Comments: ------------------------------------------------------------------------ [2003-05-18 17:42:05] sniper@php.net Don't serialize $_SESSION...or any other of those superglobal variables either. Not bug. ------------------------------------------------------------------------ [2003-05-18 17:32:07] marty at excudo dot net For an intranet application i wrote a function that can store the current position/page, by serializing the $_GET, $_POST and $_SESSION data and storing them, along with the url, in the database (except for session information that contains login-information of course). This is when i found out, that when you retrieve the serialized session data from the database, then deserialize it and put it back into the session (having unset() it first of course), php starts to mess up. Initially, the data you stored will be placed back into the session (a print_r() reveals this) and everything seems fine. But as soon as you navigate away from the page, suddenly the session data gets overwritten with the data from before the restoration procedure. (which is even more strange cause it had been unset()!). I created an example that you can try out for yourself http://www.marinesofficers.com/test/example.html that page contains screenshots, that explain once again what happens, in detail, and a link so you can actually go through the steps yourself. The bug showed on a server with PHP version 4.3.1 and i've tested it on two other servers (with a slightly lower version) as well. Same results. ------------------------------------------------------------------------ -- Edit this bug report at http://bugs.php.net/?id=23689&edit=1

« previous php.bugs (#39918) next »