Doc #76358 [Ver]: Cannot change session name when session is active

From: Date: Tue, 22 May 2018 10:03:41 +0000
Subject: Doc #76358 [Ver]: Cannot change session name when session is active
References: 1  Groups: php.doc.bugs 
Request: Send a blank email to doc-bugs+get-15702@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=76358&edit=1 ID: 76358 User updated by: tony at marston-home dot demon dot co dot uk Reported by: tony at marston-home dot demon dot co dot uk Summary: Cannot change session name when session is active Status: Verified Type: Documentation Problem Package: Session related Operating System: Windows 10 PHP Version: 7.2.5 Block user comment: N Private report: N New Comment: The fact that session_name() was mentioned in that list of changes in that GitHub page is irrelevant. The precise change, and that it broke BC, was not specified. It was NOT mentioned in any official documentation on the PHP website, and it was NOT mentioned in any change logs. Bug #71038 did not mention any problem with session_name, nor did it indicate that it would be changed. The fact that you think that it is not correct to create a new session name while a current session is active is irrelevant. That is what the function allowed for more than 15 years, and that is what the documentation said it would do. Nowhere does it say that you cannot change the session name if a session is already active. I repeat, this is an undocumented BC break that was never discussed on the php.internals group and was never voted upon, therefore I regard it as an unauthorised change. I do not see why us developers in userland should have to change our code to deal with your mistake. The old behaviour did NOT cause any problems, so I demand that you revert this change immediately. Previous Comments: ------------------------------------------------------------------------ [2018-05-22 09:21:45] requinix@php.net > If the problem was that it changed the session name but failed to return the existing name then > the CORRECT fix would > be to make it return the existing name AS WELL AS changing to the new name. The problem, as I understand it, was that it seemed like changing the session name while the session was in progress appeared to be allowed - meaning the function would not error. The fact that changing the name didn't affect the current session was secondary, even if it was more apparent. It's clear to me from the current and past implementations that session_name() was never meant to alter the current session's name. The documentation does not clarify whether the behavior it states applies if the session has or has not been started and without that I find what it says to be ambiguous. > Where was this "problem" ever reported as a bug? Not all changes to PHP require a dedicated bug report. This one came during other session fixes for bug #71038. > When was this change in behaviour ever discussed and voted upon by the internals group? Not all changes to PHP require an RFC. This one was mentioned on the internals list by @yohgaki in mid October 2016 ("Fixing insane session_start() behaviors") and the discussion lasted for a couple days without any dissenting opinions offered. > This is a BC break which has not been documented anywhere, It was listed in UPGRADING https://github.com/php/php-src/blob/PHP-7.2.0/UPGRADING however I see that it was not then added to the online migration guide. The change is deliberate but the documentation is insufficient and must be updated. If you want multiple sessions then you need to what should hopefully make sense: session_write_close() the old one (or have opened it with read_and_close=true), change the name, and session_start() to get the new one. ------------------------------------------------------------------------ [2018-05-22 08:28:21] tony at marston-home dot demon dot co dot uk There is nothing in the documentation which says that you cannot use session_name() to change the name of a session that has already started. This is a legitimate thing to do if you want to access the same session data with a new name and id. Take the following code: $name1 = session_name(); // returns 'PHPSESSID' $id1 = session_id(); // returns empty string session_start(); $name2 = session_name(); // returns 'PHPSESSID' $id2 = session_id(); // returns non-empty string session_name('NEWSESSID'); $name3 = session_name(); // returns 'PHPSESSID' instead of 'NEWSESSID' session_regenerate_id(); -- restart script to use new session Note that as of 7.2 $name3 now contains the OLD name instead of the NEW name. If the problem was that it changed the session name but failed to return the existing name then the CORRECT fix would be to make it return the existing name AS WELL AS changing to the new name. Where was this "problem" ever reported as a bug? When was this change in behaviour ever discussed and voted upon by the internals group? This is a BC break which has not been documented anywhere, nor was it ever discussed on the internals group. ------------------------------------------------------------------------ [2018-05-22 01:32:41] a at b dot c dot de The description of the function's return value says "If name is given *AND* function updates the session name, name of the old session is returned. [emphasis mine]" Like many other functions, if session_name() fails (such as when attempting to change the session name of a session has already been started), it now returns false; previously it would just fail silently and return the old name without comment. ------------------------------------------------------------------------ [2018-05-20 19:57:37] tony at marston-home dot demon dot co dot uk I already use session_name() to provide the name of the new session before I start that session with session_start(). The problem is that the function no longer works as AS ADVERTISED as it can no longer return the name of the existing session before it starts the new one. This function has worked AS ADVERISED for over 15 years, so why was it changed? For what problem is this change in behaviour supposed to be a solution? ------------------------------------------------------------------------ [2018-05-20 18:33:29] peehaa@php.net The documentation also clearly states "Thus, you need to call session_name() for every request (and before session_start() or session_register() are called)." http://php.net/manual/en/function.session-name.php ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=76358 -- Edit this bug report at https://bugs.php.net/bug.php?id=76358&edit=1

« previous php.doc.bugs (#15702) next »