PHP 4.0 Bug #3304: Transparent session handling misbehaving
| From: | peter at knowpost dot com | Date: | Mon, 24 Jan 2000 20:17:31 +0000 |
| Subject: | PHP 4.0 Bug #3304: Transparent session handling misbehaving | ||
| Groups: | php.dev | ||
| Request: | Send a blank email to php-dev+get-14887@lists.php.net to get a copy of this message | ||
From: peter@knowpost.com
Operating system: RedHat 6.0
PHP version: 4.0 Latest CVS (24/01/2000)
PHP Bug Type: Misbehaving function
Bug description: Transparent session handling misbehaving
Transparent session handling doesn't correctly handle cases like this when cookies are *not*
enabled on the browser:
<? session_start(); ?>
<A HREF="<? echo $PHP_SELF ?>">Reload</a>
The output is:
<A
HREF="?PHPSESSIONID=c4f4921a12d440baadf98415a85e6cca"/show_bug.php">Reload</a>
Also, using a script like this:
<? session_start();
echo "<A HREF=\"$REQUEST_URI\">reload</a>\n";
?>
What happens here is the session identifier is continually tagged onto the end of the URL. So the
output would be:
<A
HREF="/show_bug2.php?sid=56cb77861074df1071ae9ca6a2be042e&sid=56cb77861074df1071ae9ca6a2be042e">reload</a>,
and so on.
PHP configured using:
./configure --with-mysql --with-apxs=/usr/apache/bin/apxs --enable-trans-sid --enable-track-vars
--with-mcrypt --with-aspell --with-mm --enable-inline-optimization