#22117 [Asn->Csd]: Session vars inappropriately created as references
| From: | sniper@php.net | Date: | Thu, 22 May 2003 22:11:22 +0000 |
| Subject: | #22117 [Asn->Csd]: Session vars inappropriately created as references | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-40223@lists.php.net to get a copy of this message | ||
ID: 22117
Updated by: sniper@php.net
Reported By: phpbugs at brianmertens dot com
-Status: Assigned
+Status: Closed
Bug Type: Session related
Operating System: Win NT 4
PHP Version: 4.3.0
Assigned To: sas
New Comment:
fixed -> closed.
Previous Comments:
------------------------------------------------------------------------
[2003-05-22 16:31:23] phpbugs at brianmertens dot com
Works with 4.3.2RC4.
This seems to be fixed sometime between 4.3.0 and 4.3.2RC4.
I guess this can be closed.
------------------------------------------------------------------------
[2003-02-17 13:18:36] jneil at myersinternet dot com
While there are some new cautionary notes regarding mixing the use of
$_SESSION and session_register (and the other session functions), the
example below (and the examples in related bugs) do not mix the two
means of accessing session variables. As the session_* functions have
not been designated as deprecated code, current members of the PHP
coding community must assume that these functions are still supported
and should work. Given that the code below from brianmertens is valid
PHP syntax but yet shows a weakness in the session_register functions
(possibly due to pointer problems in the underlying code given the
nature of the error), this seems worthy of actually working on instead
of pointing out similar code (although with a different approach and
function list) that does not have the bug. Are the developers of the
PHP engine going to fix session_register or are they going to force the
thousands of PHP developers who have used this function in good faith
for several years to abandon it?
------------------------------------------------------------------------
[2003-02-10 13:03:23] sniper@php.net
Just FYI, the following script works as expected:
<?php
session_start();
if (!isset($_SESSION['var1'])) {
$_SESSION['var1'] = "INITIALIZED";
$_SESSION['var2'] = $_SESSION['var1'];
$_SESSION['var2'] = "CHANGED";
}
var_dump($_SESSION);
?>
------------------------------------------------------------------------
[2003-02-10 12:54:13] phpbugs at brianmertens dot com
A colleague points out that this script also
produces the buggy behaviour.
<?php
session_start();
$var1 = "INITIALIZED";
$var2 = $var1;
session_register("var1","var2");
$var2 = "CHANGED";
echo $var1."<br>";
echo $var2."<br>";
?>
------------------------------------------------------------------------
[2003-02-09 16:36:48] phpbugs at brianmertens dot com
Further searching makes me think that this may be
related to Bug #20583 :
http://bugs.php.net/bug.php?id=20583
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
http://bugs.php.net/22117
--
Edit this bug report at http://bugs.php.net/?id=22117&edit=1