Doc #70520 [Csd]: session_regenerate_id() "Failed to create session ID" with custom SessionHandler
| From: | yohgaki@php.net | Date: | Sat, 19 Sep 2015 08:13:04 +0000 |
| Subject: | Doc #70520 [Csd]: session_regenerate_id() "Failed to create session ID" with custom SessionHandler | ||
| References: | 1 | Groups: | php.doc.bugs |
| Request: | Send a blank email to doc-bugs+get-12770@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=70520&edit=1
ID: 70520
Updated by: yohgaki@php.net
Reported by: hpdl at oscommerce dot com
Summary: session_regenerate_id() "Failed to create session
ID" with custom SessionHandler
Status: Closed
Type: Documentation Problem
Package: Session related
Operating System: Win10
PHP Version: 7.0.0RC3
Assigned To: yohgaki
Block user comment: N
Private report: N
New Comment:
@alec
When new Zend Engine is introduced, a bug in session read is introduced.
https://bugs.php.net/bug.php?id=70529
I've fixed this today. If you would like to use "binary" session data like mcrypt
encrypted data, you'll need most recent PHP7 build.
Previous Comments:
------------------------------------------------------------------------
[2015-09-19 06:44:58] alec at alec dot pl
I've got the same issue. Don't you think the error is misleading or at least gives no clue
about where the issue is?
------------------------------------------------------------------------
[2015-09-19 01:42:41] yohgaki@php.net
New example code is in svn.
------------------------------------------------------------------------
[2015-09-19 01:41:24] yohgaki@php.net
Automatic comment from SVN on behalf of yohgaki
Revision: http://svn.php.net/viewvc/?view=revision&revision=337850
Log: Fixed bug #70520 - Update and improve example code
------------------------------------------------------------------------
[2015-09-18 22:45:22] yohgaki@php.net
Oops. I forgot to modify key string to be static string.
$key = substr(sha1(random_bytes(24)), 0, 24);
should be something like
$key = 'secret_string';
------------------------------------------------------------------------
[2015-09-18 22:41:25] yohgaki@php.net
Since mcrypt seems to have problems https://bugs.php.net/bug.php?id=70529 , I've
made new example using OpenSSL AES. Any comments on this new sample code?
There are too many ini_set() etc, I'll get rid of irrelevant code for the doc later.
<?php
ob_start();
error_reporting(E_ALL | E_STRICT);
ini_set('session.save_path', '/tmp');
ini_set('display_errors', true);
/**
* decrypt AES 256
*
* @param data $edata
* @param string $password
* @return dencrypted data
*/
function decrypt($edata, $password) {
$data = base64_decode($edata);
$salt = substr($data, 0, 16);
$ct = substr($data, 16);
$rounds = 3; // depends on key length
$data00 = $password.$salt;
$hash = array();
$hash[0] = hash('sha256', $data00, true);
$result = $hash[0];
for ($i = 1; $i < $rounds; $i++) {
$hash[$i] = hash('sha256', $hash[$i - 1].$data00, true);
$result .= $hash[$i];
}
$key = substr($result, 0, 32);
$iv = substr($result, 32,16);
return openssl_decrypt($ct, 'AES-256-CBC', $key, true, $iv);
}
/**
* crypt AES 256
*
* @param data $data
* @param string $password
* @return base64 encrypted data
*/
function encrypt($data, $password) {
// Set a random salt
$salt = openssl_random_pseudo_bytes(16);
$salted = '';
$dx = '';
// Salt the key(32) and iv(16) = 48
while (strlen($salted) < 48) {
$dx = hash('sha256', $dx.$password.$salt, true);
$salted .= $dx;
}
$key = substr($salted, 0, 32);
$iv = substr($salted, 32,16);
$encrypted_data = openssl_encrypt($data, 'AES-256-CBC', $key, true, $iv);
return base64_encode($salt . $encrypted_data);
}
class EncryptedSessionHandler extends SessionHandler
{
private $key;
public function __construct($key)
{
$this->key = $key;
}
public function read($id)
{
$data = parent::read($id);
if ($data === "") {
return "";
} else {
return decrypt($data, $this->key);
}
}
public function write($id, $data)
{
$data = encrypt($data, $this->key);
return parent::write($id, $data);
}
}
ini_set('session.save_handler', 'files');
$key = substr(sha1(random_bytes(24)), 0, 24);
$handler = new EncryptedSessionHandler($key);
session_set_save_handler($handler, true);
echo '<pre>';
session_start();
$_SESSION['key'] = 1234;
var_dump($_SESSION);
echo session_id() . PHP_EOL;
session_regenerate_id(true);
echo session_id() . PHP_EOL;
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=70520
--
Edit this bug report at https://bugs.php.net/bug.php?id=70520&edit=1