Re: PHP 4.0 Bug #5783 Updated: session_register always returns true
| From: | Albert Chin-A-Young | Date: | Wed, 23 Aug 2000 13:55:53 +0000 |
| Subject: | Re: PHP 4.0 Bug #5783 Updated: session_register always returns true | ||
| References: | 1 2 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-30383@lists.php.net to get a copy of this message | ||
On Wed, Aug 23, 2000 at 04:51:02PM +0300, Stanislav Malyshev wrote:
> AC>> Do you see this as a problem? This makes it impossible to detect at
> AC>> runtime whether or not your saved variables will be available later.
>
> They are. That's like fiving you means to check if your head is still on
> you. If it isn't, you've in deep trouble anyway, so no need for additional
> check. Same with sessions - if it cannot save, that means session module
> is dead, and no amount of checks is going to help you anyway.
It doesn't mean the session module is dead. Say you require someone to
authenticate and prompt for login/password. If they enter the correct
login/password pair, you register a variable called "logged_in".
Future pages read the list of session variables and allow viewing of
the web pages if the $logged_in variable is present. If not, the web
pages say you must first log in. Now, how do you tell if:
1. They correctly logged in but sessions are not working
2. They went to the web page directly, bypassing the login page
Both of these errors are equivalent because session_register always
returns true.
> AC>> It seems wrong to find out later that a variable you know you tried to
> AC>> save earlier is not available. Seems to make more sense to catch the
> AC>> problem as early as possible.
>
> Like when? When sessions fails to save, it gives you a warning. If it
> didn't fail, nobody can give you any kind of indication would it fail or
> not - PHP core has no extrasensory abilities.
When does it give you a warning? session_register can return true even
through your custom session handler returns false.
--
albert chin (china@thewrittenword.com)