#23689 [Bgs]: serializing - deserializing session data doesn't work
| From: | derick@php.net | Date: | Mon, 19 May 2003 10:05:03 +0000 |
| Subject: | #23689 [Bgs]: serializing - deserializing session data doesn't work | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-39941@lists.php.net to get a copy of this message | ||
ID: 23689
Updated by: derick@php.net
Reported By: marty at excudo dot net
Status: Bogus
Bug Type: Session related
Operating System: linux
PHP Version: 4.3.1
New Comment:
I'll add some warnings here and there...
Derick
Previous Comments:
------------------------------------------------------------------------
[2003-05-19 04:57:19] marty at excudo dot net
k, sorry about that status thing: as i said i wasn't sure.
Just did some more testing and i found out that the real problem was
unset($_SESSION);
I take you on your word about that *each member* thing, i am simply
reporting here, that in my case, $_SESSION = $array also works fine, as
long as i _unset_ *each member* individually (as opposed to simply
doing unset($_SESSION))
(However, i'm setting the values the clean way now, don't worry).
I do think that the manual could be a bit more specific about this.
When reading something and trying to learn, it's normal that you make
generalizations. And in the abscense of any information suggesting
otherwise (on this point in the manual) i did so too for the member
thing (unconsciously). A simple line stating that you should not try to
unset to whole session superglobal would've prevented that.
thanks for your support
------------------------------------------------------------------------
[2003-05-19 03:54:36] derick@php.net
> From the manual:
> "You can also create a session variable by simply setting
> the appropriate member of the $_SESSION"
It says *member* *of* the *$_SESSION* not $_SESSION itself. You can not
re-assign to $_SESSION, or any other super global without it losing
it's special functions. It's not a bug, leave the status set to Bogus.
------------------------------------------------------------------------
[2003-05-19 03:35:47] marty at excudo dot net
Well, i could agree on this part about the $_POST and $_GET
superglobals. In fact i think doing that is a little dirty myself. But
i do not agree about the $_SESSION superglobal!
I am simply doing what i would be doing with session_register() and
session_unregister() in PHP < 4.1!
Why is this suddenly not allowed?
From the manual:
"You can also create a session variable by simply setting the
appropriate member of the $_SESSION"
"Note: If $_SESSION is used, use unset() to unregister a session
variable."
That's all i am doing!
Could you please enlighten me why this is suddenly bogus?
(i promise i won't touch the $_POST and $_GET anymore, i simply want an
answer on the $_SESSION one)
(p.s. i changed the status back the open - i wasn't sure if this is
necessary to get another comment from you)
------------------------------------------------------------------------
[2003-05-19 01:56:31] derick@php.net
Superglobals don't work like this. You can not overwrite them by
assigning them. Not a bug -> bogus
------------------------------------------------------------------------
[2003-05-18 20:11:36] marty at excudo dot net
I'm reopening the bug.
I just did what i suggested in my last post. i created those temporary
arrays, thereby not serializing the $_SESSION data directly.
This should, in my humble opion, by allowed.
Since this:
$_SESSION['key'] = "value";
and this:
unset($_SESSION['key']);
is both valid code, i don't see how this
=>=>=>=>:
$temp_session = $_SESSION;
$serialized_session = serialize($temp_session);
<=<=<=<=:
unset($_SESSION);
$temp_session = unserialize($serialized_session);
$_SESSION = $temp_session;
is different?
However, the later produces the initial bug i reported
(if i use it in my script)
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
http://bugs.php.net/23689
--
Edit this bug report at http://bugs.php.net/?id=23689&edit=1