Doc #74231 [Asn->Opn]: Example #2 for session_regenerate_id is broken in several ways
Edit report at https://bugs.php.net/bug.php?id=74231&edit=1
ID: 74231
Updated by: kalle@php.net
Reported by: signe at cothlamadh dot net
Summary: Example #2 for session_regenerate_id is broken in
several ways
-Status: Assigned
+Status: Open
Type: Documentation Problem
Package: Documentation problem
Operating System: n/a
PHP Version: Irrelevant
-Assigned To: peehaa
+Assigned To:
Block user comment: N
Private report: N
Previous Comments:
------------------------------------------------------------------------
[2017-03-13 10:51:11] peehaa@php.net
I agree that the examples on this page are badly broken.
Will try to decipher the page later somewhere during this week and try to fix it.
------------------------------------------------------------------------
[2017-03-10 00:41:32] signe at cothlamadh dot net
Description:
------------
Example #2 does carry the caveat that it's "not fully working code," however
it's not just "not fully working" - it's badly broken, uses php.ini options
incorrectly, and non-functional.
1. The modification of use_strict_mode is wrapping the wrong function.
use_strict_mode restricts calling session_id() with a new value. Calling session_id() before
unlocking use_strict_mode will result in a logged warning.
2. The example function does _not_ preserve any existing session data, which session_regenerate_id
does. Anyone using the example would lose all session data for the user.
Before calling session_start(), you need to store the current session data temporarily in memory,
and then restore it afterward.
Documentation patch attached
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=74231&edit=1
Thread (6 messages)