Doc #66951 [Opn->Nab]: Add note that session.use_strict_mode relates only to built-in handlers
| From: | yohgaki@php.net | Date: | Sat, 27 Aug 2016 05:25:15 +0000 |
| Subject: | Doc #66951 [Opn->Nab]: Add note that session.use_strict_mode relates only to built-in handlers | ||
| References: | 1 | Groups: | php.doc.bugs |
| Request: | Send a blank email to doc-bugs+get-13859@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=66951&edit=1
ID: 66951
Updated by: yohgaki@php.net
Reported by: ondrej dot machulda at gmail dot com
Summary: Add note that session.use_strict_mode relates only
to built-in handlers
-Status: Open
+Status: Not a bug
Type: Documentation Problem
Package: Documentation problem
PHP Version: 5.5.10
Block user comment: N
Private report: N
New Comment:
No. User handlers must define session ID validation handler for session ID security. This is
mandatory in fact and all users should define the handler.
Documentation should be improved, but the bug report is not valid.
Previous Comments:
------------------------------------------------------------------------
[2014-03-24 22:31:53] ondrej dot machulda at gmail dot com
Description:
------------
The session.use_strict_mode runtime configuration option (PHP 5.5.2+) is now described in the manual
like this:
session.use_strict_mode boolean
session.use_strict_mode specifies whether the module will use strict session id mode. If this mode
is enabled, the module does not accept uninitialized session ID. If uninitialized session ID is sent
from browser, new session ID is sent to browser. Applications are protected from session fixation
via session adoption with strict mode. Defaults to 0 (disabled).
However, this is not accurate. As noted in https://bugs.php.net/bug.php?id=66947, current
behavior is related *only* to built-in session save handlers - file and mm. Once you use custom save
handler, the setting is meaningless.
As this is security setting related to CVE-2011-4718, this behavior should be documented. I propose
something like this:
Note: session.use_strict_mode applies only to PHP's built-in session save handlers. If you use
custom save handler, you must implement the strict mode yourselves.
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=66951&edit=1