Doc #73343 [Nab]: extra call to read in session_regenerate_id in custom session handler
| From: | yohgaki@php.net | Date: | Wed, 26 Oct 2016 00:32:11 +0000 |
| Subject: | Doc #73343 [Nab]: extra call to read in session_regenerate_id in custom session handler | ||
| References: | 1 | Groups: | php.doc.bugs |
| Request: | Send a blank email to doc-bugs+get-14044@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=73343&edit=1
ID: 73343
Updated by: yohgaki@php.net
Reported by: ryan dot brothers at gmail dot com
Summary: extra call to read in session_regenerate_id in
custom session handler
Status: Not a bug
Type: Documentation Problem
Package: Session related
Operating System: Linux
PHP Version: 7.1.0RC3
Assigned To: yohgaki
Block user comment: N
Private report: N
New Comment:
> if it does return something, it looks like it is being ignored anyway.
Yes. It should not read anything, even when something is went wrong (i.e. session id collision) and
it returned other session's content, session module must ignore the returned content to avoid
possible security(confidentiality) issue.
I may be better to add E_WARNING for this, but it will never happen under normal condition.
Previous Comments:
------------------------------------------------------------------------
[2016-10-25 20:03:58] ryan dot brothers at gmail dot com
Thanks, I updated my session handler to handle this. I was just more curious why read was being
called with the output being completely ignored. Yes, the second read() should not return anything,
but if it does return something, it looks like it is being ignored anyway.
------------------------------------------------------------------------
[2016-10-25 19:14:48] yohgaki@php.net
BTW, the second read() is mandatory because new session data must be locked. The second read()
should not return anything because it must be new session. It's called just to lock new
session.
If you have problem with this, you have something wrong in your save handler.
i.e. It's basically the same as
session_start();
session_commit();
$old = $_SESSION;
session_id($newid);
session_start();
$_SESSIOND = $old;
It does more things internally to keep reference to $_SESSION, but this is the basic picture.
------------------------------------------------------------------------
[2016-10-25 18:59:21] yohgaki@php.net
Oops. This change was made in PHP 7.0 and documented already.
------------------------------------------------------------------------
[2016-10-25 18:28:51] yohgaki@php.net
As a result of a bug fix, session_regenerate_id() save old session and start new session from 7.1
I've added UPGRADING.
------------------------------------------------------------------------
[2016-10-25 17:05:24] cmb@php.net
This behavioral change has been introduced by fixing bug #61470.
Is the additional read desired or necessary, Yasuo? If so, this
should probably be documented.
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=73343
--
Edit this bug report at https://bugs.php.net/bug.php?id=73343&edit=1