Doc #66951 [NEW]: Add note that session.use_strict_mode relates only to built-in handlers

From: Date: Mon, 24 Mar 2014 22:31:54 +0000
Subject: Doc #66951 [NEW]: Add note that session.use_strict_mode relates only to built-in handlers
Groups: php.doc.bugs 
Request: Send a blank email to doc-bugs+get-11089@lists.php.net to get a copy of this message
From: ondrej dot machulda at gmail dot com Operating system: PHP version: 5.5.10 Package: Documentation problem Bug Type: Documentation Problem Bug description:Add note that session.use_strict_mode relates only to built-in handlers Description: ------------ The session.use_strict_mode runtime configuration option (PHP 5.5.2+) is now described in the manual like this: session.use_strict_mode boolean session.use_strict_mode specifies whether the module will use strict session id mode. If this mode is enabled, the module does not accept uninitialized session ID. If uninitialized session ID is sent from browser, new session ID is sent to browser. Applications are protected from session fixation via session adoption with strict mode. Defaults to 0 (disabled). However, this is not accurate. As noted in https://bugs.php.net/bug.php?id=66947, current behavior is related *only* to built-in session save handlers - file and mm. Once you use custom save handler, the setting is meaningless. As this is security setting related to CVE-2011-4718, this behavior should be documented. I propose something like this: Note: session.use_strict_mode applies only to PHP's built-in session save handlers. If you use custom save handler, you must implement the strict mode yourselves. -- Edit bug report at https://bugs.php.net/bug.php?id=66951&edit=1 -- Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=66951&r=trysnapshot54 Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=66951&r=trysnapshot55 Try a snapshot (trunk): https://bugs.php.net/fix.php?id=66951&r=trysnapshottrunk Fixed in SVN: https://bugs.php.net/fix.php?id=66951&r=fixed Fixed in release: https://bugs.php.net/fix.php?id=66951&r=alreadyfixed Need backtrace: https://bugs.php.net/fix.php?id=66951&r=needtrace Need Reproduce Script: https://bugs.php.net/fix.php?id=66951&r=needscript Try newer version: https://bugs.php.net/fix.php?id=66951&r=oldversion Not developer issue: https://bugs.php.net/fix.php?id=66951&r=support Expected behavior: https://bugs.php.net/fix.php?id=66951&r=notwrong Not enough info: https://bugs.php.net/fix.php?id=66951&r=notenoughinfo Submitted twice: https://bugs.php.net/fix.php?id=66951&r=submittedtwice register_globals: https://bugs.php.net/fix.php?id=66951&r=globals PHP 4 support discontinued: https://bugs.php.net/fix.php?id=66951&r=php4 Daylight Savings: https://bugs.php.net/fix.php?id=66951&r=dst IIS Stability: https://bugs.php.net/fix.php?id=66951&r=isapi Install GNU Sed: https://bugs.php.net/fix.php?id=66951&r=gnused Floating point limitations: https://bugs.php.net/fix.php?id=66951&r=float No Zend Extensions: https://bugs.php.net/fix.php?id=66951&r=nozend MySQL Configuration Error: https://bugs.php.net/fix.php?id=66951&r=mysqlcfg

« previous php.doc.bugs (#11089) next »