Doc #66951 [NEW]: Add note that session.use_strict_mode relates only to built-in handlers
| From: | ondrej dot machulda at gmail dot com | Date: | Mon, 24 Mar 2014 22:31:54 +0000 |
| Subject: | Doc #66951 [NEW]: Add note that session.use_strict_mode relates only to built-in handlers | ||
| Groups: | php.doc.bugs | ||
| Request: | Send a blank email to doc-bugs+get-11089@lists.php.net to get a copy of this message | ||
From: ondrej dot machulda at gmail dot com
Operating system:
PHP version: 5.5.10
Package: Documentation problem
Bug Type: Documentation Problem
Bug description:Add note that session.use_strict_mode relates only to built-in handlers
Description:
------------
The session.use_strict_mode runtime configuration option (PHP 5.5.2+) is
now described in the manual like this:
session.use_strict_mode boolean
session.use_strict_mode specifies whether the module will use strict
session id mode. If this mode is enabled, the module does not accept
uninitialized session ID. If uninitialized session ID is sent from
browser, new session ID is sent to browser. Applications are protected
from session fixation via session adoption with strict mode. Defaults to
0 (disabled).
However, this is not accurate. As noted in
https://bugs.php.net/bug.php?id=66947, current
behavior is related
*only* to built-in session save handlers - file and mm. Once you use
custom save handler, the setting is meaningless.
As this is security setting related to CVE-2011-4718, this behavior
should be documented. I propose something like this:
Note: session.use_strict_mode applies only to PHP's built-in session
save handlers. If you use custom save handler, you must implement the
strict mode yourselves.
--
Edit bug report at https://bugs.php.net/bug.php?id=66951&edit=1
--
Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=66951&r=trysnapshot54
Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=66951&r=trysnapshot55
Try a snapshot (trunk): https://bugs.php.net/fix.php?id=66951&r=trysnapshottrunk
Fixed in SVN: https://bugs.php.net/fix.php?id=66951&r=fixed
Fixed in release: https://bugs.php.net/fix.php?id=66951&r=alreadyfixed
Need backtrace: https://bugs.php.net/fix.php?id=66951&r=needtrace
Need Reproduce Script: https://bugs.php.net/fix.php?id=66951&r=needscript
Try newer version: https://bugs.php.net/fix.php?id=66951&r=oldversion
Not developer issue: https://bugs.php.net/fix.php?id=66951&r=support
Expected behavior: https://bugs.php.net/fix.php?id=66951&r=notwrong
Not enough info: https://bugs.php.net/fix.php?id=66951&r=notenoughinfo
Submitted twice: https://bugs.php.net/fix.php?id=66951&r=submittedtwice
register_globals: https://bugs.php.net/fix.php?id=66951&r=globals
PHP 4 support discontinued: https://bugs.php.net/fix.php?id=66951&r=php4
Daylight Savings: https://bugs.php.net/fix.php?id=66951&r=dst
IIS Stability: https://bugs.php.net/fix.php?id=66951&r=isapi
Install GNU Sed: https://bugs.php.net/fix.php?id=66951&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=66951&r=float
No Zend Extensions: https://bugs.php.net/fix.php?id=66951&r=nozend
MySQL Configuration Error: https://bugs.php.net/fix.php?id=66951&r=mysqlcfg