PHP 4.0 Bug #3411 Updated: Transparent sessions breaking randomly
| From: | Bug Database | Date: | Sun, 06 Feb 2000 00:30:37 +0000 |
| Subject: | PHP 4.0 Bug #3411 Updated: Transparent sessions breaking randomly | ||
| Groups: | php.dev | ||
| Request: | Send a blank email to php-dev+get-15229@lists.php.net to get a copy of this message | ||
ID: 3411
User Update by: mian@thirty4.com
Status: Open
Bug Type: Misbehaving function
Description: Transparent sessions breaking randomly
With transparent session ids turned on, and cookies disabled, the auto sid function
sometimes breaks on urls that have other variables passed on the url.
SID
inserted:
href="skinview.php??sid=2a5ae9d5d09a578644ed872068ba443carea=winamp2&skin=Metallic+Nebula"
Original script:
href="skinview.php?area=winamp2&skin=Metallic+Nebula"
SID inserted:
href="profile.php?user=&sid=2a5ae9d5d09a578644ed872068ba443cshark3000"
Original script:
href="profile.php?user=shark3000"
Problem only occurs on some URLS on some of the pages, is real random, wish i could find
the connection on the broken URLS. See http://beta.skinz.org
for more live demo.
[update]
Problem is when you have half HTML / PHP URLs, the sid inserts itself before the PHP is parsed.
Above script was
<a href="/skinview.php?area=<? echo $row->area;
?>&skin=< echo urlencode($row->name); ?>">, the
sid is being inserted after the area= and then the PHP is parsed and added to the end of the
sid. I suggest parsing the full URL until the closing " of the href is found before inserting
the sid. Fixed code: <? echo "<a
href=\"/skinview.php?area=$row->area&skin=".urlencode($row->name)."\">";
?>
Please notify if/when this is fixed as the site is due to
open March 1st. Great work with the transparent sid's all up though, it saves alot of time on
developing large sites.
Full Bug description available at: http://bugs.php.net/version4/?id=3411