Bug->Doc #70520 [Ver->Ana]: session_regenerate_id() "Failed to create session ID" with custom SessionHandler

From: Date: Fri, 18 Sep 2015 09:18:27 +0000
Subject: Bug->Doc #70520 [Ver->Ana]: session_regenerate_id() "Failed to create session ID" with custom SessionHandler
References: 1  Groups: php.doc.bugs 
Request: Send a blank email to doc-bugs+get-12761@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=70520&edit=1 ID: 70520 Updated by: yohgaki@php.net Reported by: hpdl at oscommerce dot com Summary: session_regenerate_id() "Failed to create session ID" with custom SessionHandler -Status: Verified +Status: Analyzed -Type: Bug +Type: Documentation Problem Package: Session related Operating System: Win10 PHP Version: 7.0.0RC3 Assigned To: yohgaki Block user comment: N Private report: N New Comment: Found what's wrong. Current session save handler expects session read function returns STRING type when there is no error. However, the code public function read($id) { $data = parent::read($id); return @mcrypt_decrypt(MCRYPT_3DES, $this->key, $data, MCRYPT_MODE_ECB); } returns non string because $this->key is not valid key length. Apparently, the document has wrong size of key which results mcrypt_decrypt() error. This makes fail to write session data. Making documentation problem. Previous Comments: ------------------------------------------------------------------------ [2015-09-18 09:05:41] requinix@php.net I tried it with a session_save_path(".") immediately before the session_start(). CWD was a local directory, and when I ran the code I posted earlier (in the same location) it worked correctly. ------------------------------------------------------------------------ [2015-09-18 09:03:03] yohgaki@php.net I got it right. I'll check it soon. ------------------------------------------------------------------------ [2015-09-18 08:58:38] yohgaki@php.net It seems Windows only, doesn't it? I tried the save handler with php-7.0.0RC3 tag and PHP-7.0 branch on my linux box and it works. Is your session.save_path a local filesystem? i.e. It's not Windows share or like. I know some users are having problem with shared file systems. ------------------------------------------------------------------------ [2015-09-18 00:06:49] requinix@php.net Okay, I see it. So rather it's a general failure when overriding SessionHandler::write(), not about the save path. (Note that the first echo needs to be commented out as it creates output which will interfere.) Tentatively assigning to @yohgaki as he did some work with session_regenerate_id() before the RC3 release. ------------------------------------------------------------------------ [2015-09-17 23:11:47] hpdl at oscommerce dot com Sorry, the problem seems to be with custom session handlers. Below is a snippet that reproduces the problem. The handler used below is taken from the PHP documentation: http://php.net/manual/en/class.sessionhandler.php <?php error_reporting(E_ALL | E_STRICT); ini_set('display_errors', true); class EncryptedSessionHandler extends SessionHandler { private $key; public function __construct($key) { $this->key = $key; } public function read($id) { $data = parent::read($id); return @mcrypt_decrypt(MCRYPT_3DES, $this->key, $data, MCRYPT_MODE_ECB); } public function write($id, $data) { $data = @mcrypt_encrypt(MCRYPT_3DES, $this->key, $data, MCRYPT_MODE_ECB); return parent::write($id, $data); } } ini_set('session.save_handler', 'files'); $handler = new EncryptedSessionHandler('mykey'); session_set_save_handler($handler, true); session_start(); echo session_id() . '<br>'; session_regenerate_id(true); echo session_id(); ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=70520 -- Edit this bug report at https://bugs.php.net/bug.php?id=70520&edit=1

« previous php.doc.bugs (#12761) next »