PHP 4.0 Bug #6283: cannot destroy session data an unregister session variables
| From: | klaus dot habeck at berlin dot de | Date: | Mon, 21 Aug 2000 21:51:16 +0000 |
| Subject: | PHP 4.0 Bug #6283: cannot destroy session data an unregister session variables | ||
| Groups: | php.dev | ||
| Request: | Send a blank email to php-dev+get-30146@lists.php.net to get a copy of this message | ||
From: klaus.habeck@berlin.de
Operating system: Windows NT 4
PHP version: 4.0.1pl2
PHP Bug Type: Session related
Bug description: cannot destroy session data an unregister session variables
Hi folks,
In version 4.0.1pl2 the functions "session_destroy" and "session_unregister" do
not work as expected.
If I for example want to destroy unused session data and - after starting a session - try to delete
this session there is not reaction (i.e. unlinking the session file).
This function already does not work in earlier releases properly. So I unlink the file with a user
function for destroying the session data.
New in version 4.0.1pl2 is a bug in "session_unregister". While this works fine in the
betas of php4 the latest version is unable to unregister session variables.
Below you see the code, which is part of a class. This is the code that I used under php4rc2 and
that always works fine until php4pl2:
function Logout($login_url) {
session_name("HCSESSION");
session_start();
$id = session_id();
$path = session_save_path();
# session_unregister("HCUSERNAME");
# session_unregister("HCLASTNAME");
# session_unregister("HCFIRSTNAME");
# session_unregister("HCMAILADDRESS");
# session_unregister("HCEDITMODE");
session_destroy();
unlink("$path/sess_$id");
if (trim($login_url)) { header("Location: $login_url"); exit; }
return $id; }
For the security of session handling I wood be glad if you can find a solution for this bug.
Thanks a lot Klaus Habeck