#25057 [Fbk->Opn]: Session randomly changes session_id
| From: | asnagy at syr dot edu | Date: | Wed, 13 Aug 2003 15:43:38 +0000 |
| Subject: | #25057 [Fbk->Opn]: Session randomly changes session_id | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-45859@lists.php.net to get a copy of this message | ||
ID: 25057
User updated by: asnagy at syr dot edu
Reported By: asnagy at syr dot edu
-Status: Feedback
+Status: Open
Bug Type: Session related
Operating System: RH 9 Linux
PHP Version: 4.3.2
New Comment:
Seems to be working great. What was the bug?
Previous Comments:
------------------------------------------------------------------------
[2003-08-12 11:43:37] iliaa@php.net
Please try using this CVS snapshot:
http://snaps.php.net/php4-STABLE-latest.tar.gz
For Windows:
http://snaps.php.net/win32/php4-win32-STABLE-latest.zip
------------------------------------------------------------------------
[2003-08-12 11:15:43] asnagy at syr dot edu
Description:
------------
Our sessions are handled through a database. The handler functions are
managed via a class that was generated by PEAR::DB_DataObjects
For debug purposes, I print out the session_id on everypage, and the
session_id is regenerated randomly after a FEW minutes of nonuse.
The session lengths are set to 1200 seconds (20 minutes)
The session cookie expiration are also set to 20 minutes
I set the GC probability to 100/100 to test that it is being run on
every page click.
We have spent numerous hours debugging code and trying to trace it
down; but have concluded that the session_id is randomly regenerated
due to a bug in PHPs session management.
When the session is regenerated, the old session still exists fully
intact in the db, the new session is null. The cookie still exists.
If you can shed any light as to why this might be happening, I would be
extemely excited!
Reproduce code:
---------------
function read($sess_id)
{
$session = new Session();
$session->id = $sess_id;
if ($session->find(true)) {
return $session->data;
} else {
return NULL;
}
}
function write($sess_id, $data)
{
//Clear session
$session = new Session();
$session->id = $sess_id;
if ($session->find()) {
$session->delete();
}
//Create session
$session = new Session();
$session->id = $sess_id;
$session->stamp = 'NOW()';
$session->data = $data;
$session->insert();
return true;
}
function destroy($sess_id)
{
$session = new Session();
$session->id = $sess_id;
return $session->delete();
}
function gc($max_lifetime)
{
global $db;
$smarty = new Smarty();
$id = '';
$sql = "stamp < NOW() - CAST('" . $max_lifetime .
" seconds' AS INTERVAL)";
$result = $db->query("SELECT id FROM session WHERE " . $sql);
while ($row = $result->fetchRow()) {
$smarty->clear_cache(null, $row['id']);
$id .= $row['id'] . ' ';
}
$db->query("DELETE FROM session WHERE " .
"(data IS NULL OR data NOT LIKE '%username%') OR " .
$sql);
return true;
}
------------------------------------------------------------------------
--
Edit this bug report at http://bugs.php.net/?id=25057&edit=1