PHP 4.0 Bug #5887: Difficulty with session handlers

From: Date: Tue, 01 Aug 2000 04:00:54 +0000
Subject: PHP 4.0 Bug #5887: Difficulty with session handlers
Groups: php.dev 
Request: Send a blank email to php-dev+get-27169@lists.php.net to get a copy of this message
From: michael@michaelsmacshack.com Operating system: Caldera - 2.3 PHP version: 4.0.1pl2 PHP Bug Type: Session related Bug description: Difficulty with session handlers First I have read the documentation both on this site and at ZEND.<br> The test case was taken from the artical "PHP4 Customer Session <br> Handler Test Script" by Ying Zhang (ying@zippydesign.com) at the<br> HTTP://www.phpbuilder.com site.<br> <br> This is a complex issue. It would be reasonable to expect PHP4 to<br> behave according to what is set in PHP.ini as a default.... <br> The following are my results using PHP4.0.1pl2.<br> <br> 1) With 'session.save_handler' not defined (commented out):<br> <br> The online documentation for the session_module_name states that <br> the 'module' can be set in the call:<br> "session_module_name() returns the name of the current <br> session module. If module is specified, that module <br> will be used instead."<br> <br> Any attempt to do so results in an error regardless of whether<br> or not any handler has been defined by the user:<br> Fatal error: Failed to initialize session module in <br> .../handler/test.php on line 38 <br> This occurs at the session_start() call.<br> <br> Not setting a 'module' will return the current handler. With<br> nothing defined in PHP.ini, a value of 'files' is returned.<br> <br> If you define your 'user' handlers and call 'session_set_save_handler'<br> before the 'session_module_name' call, a value of user is returned.<br> However, any variables registered in this session Do Not maintain<br> their value. It is like the handlers are accepted, but are not used.<br> <br> Thus, not having 'session.save_handler' defined in PHP.ini does not<br> help. However, the 'files' modules does work (e.g. no defined user<br> handlers) in this situation.<br> <br> 2) If we define 'session.save_handler' in PHP.ini with a value of 'files',<br> then the same results as above occur.<br> <br> Thus in this case, we have explicitly defined the handler as file and<br> the only thing that works is the 'files' module.<br> <br> 3) If we define the 'session.save_handler' in PHP.ini with a value of<br> 'user', then things change to the opposite. You must define an <br> user handler. If you do not, registered variables are not retained.<br> <br> Thus the 'user' module dos work in this case and the variables are<br> passed from invocation to invocation.<br> <br> This leaves us with the following:<br> a. One handler method can be defined at a time. And only one.<br> b. There is a very tight coupling between the PHP.ini file and<br> what can be done by the programmer.<br> <br> Conclusions. You can get a 'user' handler defined to track the session<br> data in a database. But, it must be only one way for all applications.<br> (It could be different databases for different applications however.)<br> It would seem that this is wrong. It should be reasonable to define one<br> behavior for one application and another for others.<br> <br> I hope this has help to clear up a few questions.

« previous php.dev (#27169) next »