#22117 [Asn->Csd]: Session vars inappropriately created as references

From: Date: Thu, 22 May 2003 22:11:22 +0000
Subject: #22117 [Asn->Csd]: Session vars inappropriately created as references
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-40223@lists.php.net to get a copy of this message
ID: 22117 Updated by: sniper@php.net Reported By: phpbugs at brianmertens dot com -Status: Assigned +Status: Closed Bug Type: Session related Operating System: Win NT 4 PHP Version: 4.3.0 Assigned To: sas New Comment: fixed -> closed. Previous Comments: ------------------------------------------------------------------------ [2003-05-22 16:31:23] phpbugs at brianmertens dot com Works with 4.3.2RC4. This seems to be fixed sometime between 4.3.0 and 4.3.2RC4. I guess this can be closed. ------------------------------------------------------------------------ [2003-02-17 13:18:36] jneil at myersinternet dot com While there are some new cautionary notes regarding mixing the use of $_SESSION and session_register (and the other session functions), the example below (and the examples in related bugs) do not mix the two means of accessing session variables. As the session_* functions have not been designated as deprecated code, current members of the PHP coding community must assume that these functions are still supported and should work. Given that the code below from brianmertens is valid PHP syntax but yet shows a weakness in the session_register functions (possibly due to pointer problems in the underlying code given the nature of the error), this seems worthy of actually working on instead of pointing out similar code (although with a different approach and function list) that does not have the bug. Are the developers of the PHP engine going to fix session_register or are they going to force the thousands of PHP developers who have used this function in good faith for several years to abandon it? ------------------------------------------------------------------------ [2003-02-10 13:03:23] sniper@php.net Just FYI, the following script works as expected: <?php session_start(); if (!isset($_SESSION['var1'])) { $_SESSION['var1'] = "INITIALIZED"; $_SESSION['var2'] = $_SESSION['var1']; $_SESSION['var2'] = "CHANGED"; } var_dump($_SESSION); ?> ------------------------------------------------------------------------ [2003-02-10 12:54:13] phpbugs at brianmertens dot com A colleague points out that this script also produces the buggy behaviour. <?php session_start(); $var1 = "INITIALIZED"; $var2 = $var1; session_register("var1","var2"); $var2 = "CHANGED"; echo $var1."<br>"; echo $var2."<br>"; ?> ------------------------------------------------------------------------ [2003-02-09 16:36:48] phpbugs at brianmertens dot com Further searching makes me think that this may be related to Bug #20583 : http://bugs.php.net/bug.php?id=20583 ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at http://bugs.php.net/22117 -- Edit this bug report at http://bugs.php.net/?id=22117&edit=1

« previous php.bugs (#40223) next »