Doc #70520 [Csd]: session_regenerate_id() "Failed to create session ID" with custom SessionHandler

From: Date: Sat, 19 Sep 2015 08:13:04 +0000
Subject: Doc #70520 [Csd]: session_regenerate_id() "Failed to create session ID" with custom SessionHandler
References: 1  Groups: php.doc.bugs 
Request: Send a blank email to doc-bugs+get-12770@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=70520&edit=1 ID: 70520 Updated by: yohgaki@php.net Reported by: hpdl at oscommerce dot com Summary: session_regenerate_id() "Failed to create session ID" with custom SessionHandler Status: Closed Type: Documentation Problem Package: Session related Operating System: Win10 PHP Version: 7.0.0RC3 Assigned To: yohgaki Block user comment: N Private report: N New Comment: @alec When new Zend Engine is introduced, a bug in session read is introduced. https://bugs.php.net/bug.php?id=70529 I've fixed this today. If you would like to use "binary" session data like mcrypt encrypted data, you'll need most recent PHP7 build. Previous Comments: ------------------------------------------------------------------------ [2015-09-19 06:44:58] alec at alec dot pl I've got the same issue. Don't you think the error is misleading or at least gives no clue about where the issue is? ------------------------------------------------------------------------ [2015-09-19 01:42:41] yohgaki@php.net New example code is in svn. ------------------------------------------------------------------------ [2015-09-19 01:41:24] yohgaki@php.net Automatic comment from SVN on behalf of yohgaki Revision: http://svn.php.net/viewvc/?view=revision&amp;revision=337850 Log: Fixed bug #70520 - Update and improve example code ------------------------------------------------------------------------ [2015-09-18 22:45:22] yohgaki@php.net Oops. I forgot to modify key string to be static string. $key = substr(sha1(random_bytes(24)), 0, 24); should be something like $key = 'secret_string'; ------------------------------------------------------------------------ [2015-09-18 22:41:25] yohgaki@php.net Since mcrypt seems to have problems https://bugs.php.net/bug.php?id=70529 , I've made new example using OpenSSL AES. Any comments on this new sample code? There are too many ini_set() etc, I'll get rid of irrelevant code for the doc later. <?php ob_start(); error_reporting(E_ALL | E_STRICT); ini_set('session.save_path', '/tmp'); ini_set('display_errors', true); /** * decrypt AES 256 * * @param data $edata * @param string $password * @return dencrypted data */ function decrypt($edata, $password) { $data = base64_decode($edata); $salt = substr($data, 0, 16); $ct = substr($data, 16); $rounds = 3; // depends on key length $data00 = $password.$salt; $hash = array(); $hash[0] = hash('sha256', $data00, true); $result = $hash[0]; for ($i = 1; $i < $rounds; $i++) { $hash[$i] = hash('sha256', $hash[$i - 1].$data00, true); $result .= $hash[$i]; } $key = substr($result, 0, 32); $iv = substr($result, 32,16); return openssl_decrypt($ct, 'AES-256-CBC', $key, true, $iv); } /** * crypt AES 256 * * @param data $data * @param string $password * @return base64 encrypted data */ function encrypt($data, $password) { // Set a random salt $salt = openssl_random_pseudo_bytes(16); $salted = ''; $dx = ''; // Salt the key(32) and iv(16) = 48 while (strlen($salted) < 48) { $dx = hash('sha256', $dx.$password.$salt, true); $salted .= $dx; } $key = substr($salted, 0, 32); $iv = substr($salted, 32,16); $encrypted_data = openssl_encrypt($data, 'AES-256-CBC', $key, true, $iv); return base64_encode($salt . $encrypted_data); } class EncryptedSessionHandler extends SessionHandler { private $key; public function __construct($key) { $this->key = $key; } public function read($id) { $data = parent::read($id); if ($data === "") { return ""; } else { return decrypt($data, $this->key); } } public function write($id, $data) { $data = encrypt($data, $this->key); return parent::write($id, $data); } } ini_set('session.save_handler', 'files'); $key = substr(sha1(random_bytes(24)), 0, 24); $handler = new EncryptedSessionHandler($key); session_set_save_handler($handler, true); echo '<pre>'; session_start(); $_SESSION['key'] = 1234; var_dump($_SESSION); echo session_id() . PHP_EOL; session_regenerate_id(true); echo session_id() . PHP_EOL; ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=70520 -- Edit this bug report at https://bugs.php.net/bug.php?id=70520&edit=1

« previous php.doc.bugs (#12770) next »