Doc #73343 [Nab]: extra call to read in session_regenerate_id in custom session handler

From: Date: Wed, 26 Oct 2016 00:32:11 +0000
Subject: Doc #73343 [Nab]: extra call to read in session_regenerate_id in custom session handler
References: 1  Groups: php.doc.bugs 
Request: Send a blank email to doc-bugs+get-14044@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=73343&edit=1 ID: 73343 Updated by: yohgaki@php.net Reported by: ryan dot brothers at gmail dot com Summary: extra call to read in session_regenerate_id in custom session handler Status: Not a bug Type: Documentation Problem Package: Session related Operating System: Linux PHP Version: 7.1.0RC3 Assigned To: yohgaki Block user comment: N Private report: N New Comment: > if it does return something, it looks like it is being ignored anyway. Yes. It should not read anything, even when something is went wrong (i.e. session id collision) and it returned other session's content, session module must ignore the returned content to avoid possible security(confidentiality) issue. I may be better to add E_WARNING for this, but it will never happen under normal condition. Previous Comments: ------------------------------------------------------------------------ [2016-10-25 20:03:58] ryan dot brothers at gmail dot com Thanks, I updated my session handler to handle this. I was just more curious why read was being called with the output being completely ignored. Yes, the second read() should not return anything, but if it does return something, it looks like it is being ignored anyway. ------------------------------------------------------------------------ [2016-10-25 19:14:48] yohgaki@php.net BTW, the second read() is mandatory because new session data must be locked. The second read() should not return anything because it must be new session. It's called just to lock new session. If you have problem with this, you have something wrong in your save handler. i.e. It's basically the same as session_start(); session_commit(); $old = $_SESSION; session_id($newid); session_start(); $_SESSIOND = $old; It does more things internally to keep reference to $_SESSION, but this is the basic picture. ------------------------------------------------------------------------ [2016-10-25 18:59:21] yohgaki@php.net Oops. This change was made in PHP 7.0 and documented already. ------------------------------------------------------------------------ [2016-10-25 18:28:51] yohgaki@php.net As a result of a bug fix, session_regenerate_id() save old session and start new session from 7.1 I've added UPGRADING. ------------------------------------------------------------------------ [2016-10-25 17:05:24] cmb@php.net This behavioral change has been introduced by fixing bug #61470. Is the additional read desired or necessary, Yasuo? If so, this should probably be documented. ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=73343 -- Edit this bug report at https://bugs.php.net/bug.php?id=73343&edit=1

« previous php.doc.bugs (#14044) next »