Bug->Doc #76358 [Nab->Ver]: Cannot change session name when session is active
| From: | requinix@php.net | Date: | Tue, 22 May 2018 09:21:51 +0000 |
| Subject: | Bug->Doc #76358 [Nab->Ver]: Cannot change session name when session is active | ||
| References: | 1 | Groups: | php.doc.bugs |
| Request: | Send a blank email to doc-bugs+get-15701@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=76358&edit=1
ID: 76358
Updated by: requinix@php.net
Reported by: tony at marston-home dot demon dot co dot uk
Summary: Cannot change session name when session is active
-Status: Not a bug
+Status: Verified
-Type: Bug
+Type: Documentation Problem
Package: Session related
Operating System: Windows 10
PHP Version: 7.2.5
Block user comment: N
Private report: N
New Comment:
> If the problem was that it changed the session name but failed to return the existing name then
> the CORRECT fix would
> be to make it return the existing name AS WELL AS changing to the new name.
The problem, as I understand it, was that it seemed like changing the session name while the session
was in progress appeared to be allowed - meaning the function would not error. The fact that
changing the name didn't affect the current session was secondary, even if it was more
apparent.
It's clear to me from the current and past implementations that session_name() was never meant
to alter the current session's name. The documentation does not clarify whether the behavior it
states applies if the session has or has not been started and without that I find what it says to be
ambiguous.
> Where was this "problem" ever reported as a bug?
Not all changes to PHP require a dedicated bug report. This one came during other session fixes for
bug #71038.
> When was this change in behaviour ever discussed and voted upon by the internals group?
Not all changes to PHP require an RFC. This one was mentioned on the internals list by @yohgaki in
mid October 2016 ("Fixing insane session_start() behaviors") and the discussion lasted for
a couple days without any dissenting opinions offered.
> This is a BC break which has not been documented anywhere,
It was listed in UPGRADING
https://github.com/php/php-src/blob/PHP-7.2.0/UPGRADING
however I see that it was not then added to the online migration guide.
The change is deliberate but the documentation is insufficient and must be updated.
If you want multiple sessions then you need to what should hopefully make sense:
session_write_close() the old one (or have opened it with read_and_close=true), change the name, and
session_start() to get the new one.
Previous Comments:
------------------------------------------------------------------------
[2018-05-22 08:28:21] tony at marston-home dot demon dot co dot uk
There is nothing in the documentation which says that you cannot use session_name() to change the
name of a session that has already started. This is a legitimate thing to do if you want to access
the same session data with a new name and id. Take the following code:
$name1 = session_name(); // returns 'PHPSESSID'
$id1 = session_id(); // returns empty string
session_start();
$name2 = session_name(); // returns 'PHPSESSID'
$id2 = session_id(); // returns non-empty string
session_name('NEWSESSID');
$name3 = session_name(); // returns 'PHPSESSID' instead of 'NEWSESSID'
session_regenerate_id();
-- restart script to use new session
Note that as of 7.2 $name3 now contains the OLD name instead of the NEW name.
If the problem was that it changed the session name but failed to return the existing name then the
CORRECT fix would be to make it return the existing name AS WELL AS changing to the new name.
Where was this "problem" ever reported as a bug?
When was this change in behaviour ever discussed and voted upon by the internals group?
This is a BC break which has not been documented anywhere, nor was it ever discussed on the
internals group.
------------------------------------------------------------------------
[2018-05-22 01:32:41] a at b dot c dot de
The description of the function's return value says
"If name is given *AND* function updates the session name, name of the old session is returned.
[emphasis mine]"
Like many other functions, if session_name() fails (such as when attempting to change the session
name of a session has already been started), it now returns false; previously it would just fail
silently and return the old name without comment.
------------------------------------------------------------------------
[2018-05-20 19:57:37] tony at marston-home dot demon dot co dot uk
I already use session_name() to provide the name of the new session before I start that session with
session_start(). The problem is that the function no longer works as AS ADVERTISED as it can no
longer return the name of the existing session before it starts the new one.
This function has worked AS ADVERISED for over 15 years, so why was it changed? For what problem is
this change in behaviour supposed to be a solution?
------------------------------------------------------------------------
[2018-05-20 18:33:29] peehaa@php.net
The documentation also clearly states "Thus, you need to call session_name() for every request
(and before session_start() or session_register() are called)."
http://php.net/manual/en/function.session-name.php
------------------------------------------------------------------------
[2018-05-20 17:19:50] tony at marston-home dot demon dot co dot uk
Description:
------------
This error was introduced in 7.2 for no good reason. I have been using this technique since 2003 to
enable a user to have multiple sessions on the same PC, each with its own name and ID. This now
fails.
I know that https://bugs.php.net/bug.php?id=75650 has declared
that this not a bug, but I strongly disagree.
Why was this change made? What was the reasoning? If this usage does not cause a problem in the
engine then why is it now being disallowed? If this is someone's idea of "purity"
then that someone needs a good talking to as this is overstepping the mark.
Test script:
---------------
session_start();
$old_name = session_name('NEWSESSION'); // with 7.2 this now returns FALSE
session_regenerate_id();
⦠do something
session_name($old_name); // with 7.2 this now fails as $old_name is FALSE
Expected result:
----------------
I expect session_name() to do what it has been doing for the past 15 years, that is to return the
existing session name while assigning a new one. The documentation clearly states "Get and/or
set the current session name", and the "and/or" indicates that it should be able to
do both at the same time.
Actual result:
--------------
session_name() returns FALSE instead of the current session name.
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=76358&edit=1