PHP 4.0 Bug #5887: Difficulty with session handlers
| From: | michael at michaelsmacshack dot com | Date: | Tue, 01 Aug 2000 04:00:54 +0000 |
| Subject: | PHP 4.0 Bug #5887: Difficulty with session handlers | ||
| Groups: | php.dev | ||
| Request: | Send a blank email to php-dev+get-27169@lists.php.net to get a copy of this message | ||
From: michael@michaelsmacshack.com
Operating system: Caldera - 2.3
PHP version: 4.0.1pl2
PHP Bug Type: Session related
Bug description: Difficulty with session handlers
First I have read the documentation both on this site and at ZEND.<br>
The test case was taken from the artical "PHP4 Customer Session <br>
Handler Test Script" by Ying Zhang (ying@zippydesign.com) at the<br>
HTTP://www.phpbuilder.com site.<br>
<br>
This is a complex issue. It would be reasonable to expect PHP4 to<br>
behave according to what is set in PHP.ini as a default.... <br>
The following are my results using PHP4.0.1pl2.<br>
<br>
1) With 'session.save_handler' not defined (commented out):<br>
<br>
The online documentation for the session_module_name states that <br>
the 'module' can be set in the call:<br>
"session_module_name() returns the name of the current <br>
session module. If module is specified, that module <br>
will be used instead."<br>
<br>
Any attempt to do so results in an error regardless of whether<br>
or not any handler has been defined by the user:<br>
Fatal error: Failed to initialize session module in <br>
.../handler/test.php on line 38 <br>
This occurs at the session_start() call.<br>
<br>
Not setting a 'module' will return the current handler. With<br>
nothing defined in PHP.ini, a value of 'files' is returned.<br>
<br>
If you define your 'user' handlers and call
'session_set_save_handler'<br>
before the 'session_module_name' call, a value of user is returned.<br>
However, any variables registered in this session Do Not maintain<br>
their value. It is like the handlers are accepted, but are not used.<br>
<br>
Thus, not having 'session.save_handler' defined in PHP.ini does not<br>
help. However, the 'files' modules does work (e.g. no defined user<br>
handlers) in this situation.<br>
<br>
2) If we define 'session.save_handler' in PHP.ini with a value of
'files',<br>
then the same results as above occur.<br>
<br>
Thus in this case, we have explicitly defined the handler as file and<br>
the only thing that works is the 'files' module.<br>
<br>
3) If we define the 'session.save_handler' in PHP.ini with a value of<br>
'user', then things change to the opposite. You must define an <br>
user handler. If you do not, registered variables are not retained.<br>
<br>
Thus the 'user' module dos work in this case and the variables are<br>
passed from invocation to invocation.<br>
<br>
This leaves us with the following:<br>
a. One handler method can be defined at a time. And only one.<br>
b. There is a very tight coupling between the PHP.ini file and<br>
what can be done by the programmer.<br>
<br>
Conclusions. You can get a 'user' handler defined to track the session<br>
data in a database. But, it must be only one way for all applications.<br>
(It could be different databases for different applications however.)<br>
It would seem that this is wrong. It should be reasonable to define one<br>
behavior for one application and another for others.<br>
<br>
I hope this has help to clear up a few questions.