Doc #76413 [Ver]: session_name() documentation is wrong
Edit report at https://bugs.php.net/bug.php?id=76413&edit=1
ID: 76413
Updated by: yohgaki@php.net
Reported by: tony at marston-home dot demon dot co dot uk
Summary: session_name() documentation is wrong
Status: Verified
Type: Documentation Problem
Package: Session related
PHP Version: 7.2.6
Block user comment: N
Private report: N
New Comment:
PHP 7.2' session module detects unworkable / problematic session function usages as it should.
If I miss some descriptions, please let me know.
Previous Comments:
------------------------------------------------------------------------
[2018-06-06 10:08:53] yohgaki@php.net
"Already sent cookie" was checked at session_start() previously. Therefore I forgot about
added cookie check.
Older PHPs had cookie already sent errors. PHP 7.2 notifies unworkable code a bit earlier.
That's all.
------------------------------------------------------------------------
[2018-06-06 09:58:34] tony at marston-home dot demon dot co dot uk
If you are not sure who does the update then you need to check. Try running the following code:
<?php
$dump = print_r($_COOKIE, true);
$name = session_name();
session_name('newname'); // cookie will not show up until next run
exit;
Now try running it again. You will see that $_COOKIE does NOT contain an entry for
'newname'. This is because the cookie is NOT created by session_name(). It is only created
with the subsequent call to session_start() when both the name and id are available.
The documentation is NOT accurate, therefore it should be amended.
------------------------------------------------------------------------
[2018-06-06 09:57:56] yohgaki@php.net
Oops. These were added since it simply does not work if cookie is already sent.
TranSID wouldn't work correctly once output is started also.
Since it does no work anyway, it's just a error notification.
------------------------------------------------------------------------
[2018-06-06 09:50:09] requinix@php.net
The problem is the docs now say "session_name() modifies HTTP cookie", which sounds like
calling session_name *changes* the cookie after it has already been set with session_start(). It
does not. But I think I understand the intention behind this addition: it's trying to say that
session_name (and thus session.name) are *used* in the cookie, so changing the value will affect
what the cookie *will include* when the session *is started later*.
I don't know that this addition even needs to be in the documentation for session_name() at all
- it should be explained in the rest of the session docs already. But in order to keep it, a better
explanation could be
> session_name() controls the name portion of the HTTP cookie used for sessions (if using
> cookies), and when a new
> session name is supplied then session_start() will use the new name. session_name() cannot be
> used when a session
> has already started, but the session can be closed, the name changed, and the session
> restarted. session_name()
> also cannot be used if headers have already been sent.
(see also bug #76358)
Then similar language for session_id() and the other functions that change session INI settings.
------------------------------------------------------------------------
[2018-06-06 09:28:14] yohgaki@php.net
I'm not sure who does the update, but sentence is correct.
Cookie sent checks(session_id() and session_name()) were there for a long time.
Try "php -a", then
echo 1
session_name('new'); // or session_id('new');
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=76413
--
Edit this bug report at https://bugs.php.net/bug.php?id=76413&edit=1
Thread (8 messages)