Bug->Doc #75047 [Opn]: session_regenerate_id fails with redis
| From: | yohgaki@php.net | Date: | Tue, 05 Sep 2017 23:00:45 +0000 |
| Subject: | Bug->Doc #75047 [Opn]: session_regenerate_id fails with redis | ||
| References: | 1 | Groups: | php.doc.bugs |
| Request: | Send a blank email to doc-bugs+get-14956@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=75047&edit=1
ID: 75047
Updated by: yohgaki@php.net
Reported by: bartosz at kibilko dot pl
Summary: session_regenerate_id fails with redis
Status: Open
-Type: Bug
+Type: Documentation Problem
-Package: Unknown/Other Function
+Package: Session related
Operating System: Ubuntu / Docker Container
PHP Version: 7.0.22
-Assigned To:
+Assigned To: yohgaki
Block user comment: N
Private report: N
New Comment:
Make this a doc bug.
Previous Comments:
------------------------------------------------------------------------
[2017-09-05 21:32:45] yohgaki@php.net
It seems I missed to document it code, too :(
I'll update both UPGRADING and comment in the code.
------------------------------------------------------------------------
[2017-09-05 21:00:02] yohgaki@php.net
I missed to write upgrading note to UPGRADING. However, I wrote enough comments to
ttps://github.com/php/php-src/blob/master/ext/session/mod_files.c
for native session save handler developers as a reference implementation, but the comment is deleted
by someone else.
I guess that's the reason why phpredis misses required code...
------------------------------------------------------------------------
[2017-09-05 09:39:23] yohgaki@php.net
BTW, this is caused due to session_regenerate_id() behavior change from PHP 7.0.
PHP 5.6 and less
- Old session data is not saved and creates new session without validating SID
PHP 7.0 and up
- Old session data is saved and creates new session with SID validation.
From PHP 7.0, session save handlers are required not only to implement SID validation function, but
also create session data either at "open" or "read" to make SID validation work.
I might have missed this in UPGRADING.
------------------------------------------------------------------------
[2017-09-05 08:40:26] yohgaki@php.net
> The reason that this problem exists is because PHP doesn't create the key
> in Redis if it doesn't exist. As a work-around, you need to create a key if
> one doesn't exist in the read() function of your session handler class.
> This removed the problem from my error logs:
Thank you for useful info.
I take a look at the code for session save handler "read" and "write" in
phpredis.
https://github.com/phpredis/phpredis/blob/develop/redis_session.c#L342
https://github.com/phpredis/phpredis/blob/develop/redis_session.c#L402
Session "read" does not send write command to redis for empty get, so it seems this is
phpredis session save handler bug.
Save handlers are supposed to create session ID data entry either
- open
or
- read
When data is created is depends on underlying storage. For instance, "files" cannot create
session data file with "read" since file is created when it is opened.
On the other hand, storage like redis/postgresql/etc cannot create session data with
"open", but "read". "open" is supposed to open connection to db.
"open" may create session data entry, though.
It seems this is phpredis issue, please close this bug if you get this fixed. If not, please let me
know issue is in session.
------------------------------------------------------------------------
[2017-09-05 06:20:40] ray at rayxis dot com
I'm also experiencing this in php 7.1.8.
The reason that this problem exists is because PHP doesn't create the key in Redis if it
doesn't exist. As a work-around, you need to create a key if one doesn't exist in the
read() function of your session handler class. This removed the problem from my error logs:
public function read ($key)
{
// Get the session data and extend the expiration.
$nkey = $this->prefix . $key;
read:
$data = $this->sess->get($nkey);
// If nothing exists, create it first because PHP has a bug. :(
if (!$data)
{
$this->write($key,TRUE);
goto read;
}
$this->sess->expire($key, getenv('SESSTTL'));
// Return the result.
return $data;
}
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=75047
--
Edit this bug report at https://bugs.php.net/bug.php?id=75047&edit=1