Re: PHP 4.0 Bug #5783 Updated: session_register always returns true

From: Date: Wed, 23 Aug 2000 13:55:53 +0000
Subject: Re: PHP 4.0 Bug #5783 Updated: session_register always returns true
References: 1 2  Groups: php.dev 
Request: Send a blank email to php-dev+get-30383@lists.php.net to get a copy of this message
On Wed, Aug 23, 2000 at 04:51:02PM +0300, Stanislav Malyshev wrote: > AC>> Do you see this as a problem? This makes it impossible to detect at > AC>> runtime whether or not your saved variables will be available later. > > They are. That's like fiving you means to check if your head is still on > you. If it isn't, you've in deep trouble anyway, so no need for additional > check. Same with sessions - if it cannot save, that means session module > is dead, and no amount of checks is going to help you anyway. It doesn't mean the session module is dead. Say you require someone to authenticate and prompt for login/password. If they enter the correct login/password pair, you register a variable called "logged_in". Future pages read the list of session variables and allow viewing of the web pages if the $logged_in variable is present. If not, the web pages say you must first log in. Now, how do you tell if: 1. They correctly logged in but sessions are not working 2. They went to the web page directly, bypassing the login page Both of these errors are equivalent because session_register always returns true. > AC>> It seems wrong to find out later that a variable you know you tried to > AC>> save earlier is not available. Seems to make more sense to catch the > AC>> problem as early as possible. > > Like when? When sessions fails to save, it gives you a warning. If it > didn't fail, nobody can give you any kind of indication would it fail or > not - PHP core has no extrasensory abilities. When does it give you a warning? session_register can return true even through your custom session handler returns false. -- albert chin (china@thewrittenword.com)

« previous php.dev (#30383) next »