Doc #76413 [Nab->Ver]: session_name() documentation is wrong

From: Date: Wed, 06 Jun 2018 09:50:11 +0000
Subject: Doc #76413 [Nab->Ver]: session_name() documentation is wrong
References: 1  Groups: php.doc.bugs 
Request: Send a blank email to doc-bugs+get-15740@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=76413&edit=1

 ID:                 76413
 Updated by:         requinix@php.net
 Reported by:        tony at marston-home dot demon dot co dot uk
 Summary:            session_name() documentation is wrong
-Status:             Not a bug
+Status:             Verified
 Type:               Documentation Problem
 Package:            Session related
 PHP Version:        7.2.6
-Assigned To:        yohgaki
+Assigned To:        
 Block user comment: N
 Private report:     N

 New Comment:

The problem is the docs now say "session_name() modifies HTTP cookie", which sounds like
calling session_name *changes* the cookie after it has already been set with session_start(). It
does not. But I think I understand the intention behind this addition: it's trying to say that
session_name (and thus session.name) are *used* in the cookie, so changing the value will affect
what the cookie *will include* when the session *is started later*.

I don't know that this addition even needs to be in the documentation for session_name() at all
- it should be explained in the rest of the session docs already. But in order to keep it, a better
explanation could be

> session_name() controls the name portion of the HTTP cookie used for sessions (if using
> cookies), and when a new
> session name is supplied then session_start() will use the new name. session_name() cannot be
> used when a session
> has already started, but the session can be closed, the name changed, and the session
> restarted. session_name()
> also cannot be used if headers have already been sent.

(see also bug #76358)

Then similar language for session_id() and the other functions that change session INI settings.


Previous Comments:
------------------------------------------------------------------------
[2018-06-06 09:28:14] yohgaki@php.net

I'm not sure who does the update, but sentence is correct.
Cookie sent checks(session_id() and session_name()) were there for a long time.

Try "php -a", then
echo 1
session_name('new'); // or session_id('new');

------------------------------------------------------------------------
[2018-06-05 09:49:51] tony at marston-home dot demon dot co dot uk

Description:
------------
The manual page for session_name() has recently been updated to include the following:

"When new session name is supplied, session_name() modifies HTTP cookie (and output contents
when session.transid is enabled). Once HTTP cookie is sent, session_name() raises error."

I have run several tests, and I cannot see this behaviour, nor has it ever been the behaviour in all
past versions of PHP.

Changing the session name does not create or modify any cookies. Session cookies are only created
with session-start() and modified with session_regenerate_id().

It is also possible to create a cookie before calling session_name('newname') without any
error.



------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=76413&edit=1


Thread (8 messages)

« previous php.doc.bugs (#15740) next »