Doc #77384 [Opn->Csd]: Unable to change Session Save Handler to "user"
| From: | cmb@php.net | Date: | Fri, 04 Jan 2019 18:37:20 +0000 |
| Subject: | Doc #77384 [Opn->Csd]: Unable to change Session Save Handler to "user" | ||
| References: | 1 | Groups: | php.doc.bugs |
| Request: | Send a blank email to doc-bugs+get-16295@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=77384&edit=1
ID: 77384
Updated by: cmb@php.net
Reported by: info at dreamtimeshop dot com
Summary: Unable to change Session Save Handler to "user"
-Status: Open
+Status: Closed
Type: Documentation Problem
Package: Session related
Operating System: Windows, Linux
PHP Version: 7.2.0
-Assigned To:
+Assigned To: cmb
Block user comment: N
Private report: N
New Comment:
This bug has been fixed in the documentation's XML sources. Since the
online and downloadable versions of the documentation need some time
to get updated, we would like to ask you to be a bit patient.
Thank you for the report, and for helping us make our documentation better.
Previous Comments:
------------------------------------------------------------------------
[2019-01-04 18:36:38] cmb@php.net
Automatic comment from SVN on behalf of cmb
Revision: http://svn.php.net/viewvc/?view=revision&revision=346542
Log: Fix #77384: Unable to change Session Save Handler to "user"
------------------------------------------------------------------------
[2019-01-04 13:09:51] nikic@php.net
Right, the documentation clearly needs some updates here. We should have a note in the PHP 7.2
upgrading guide, and also mention on the session_module_name page that you can't explicitly set
it to 'user' and should use session_set_save_handler() instead.
------------------------------------------------------------------------
[2019-01-04 12:58:52] info at dreamtimeshop dot com
oops... sorry, I am still a bit confused after the long holidays :-) ...
The docu page is http://php.net/manual/en/function.session-module-name.php
and there is not much in it. After all it says, it can "Get and/or set the current session
module", and obviously nothing has changed since a long time, I tried to set ("as
always"), and got those error messages.
------------------------------------------------------------------------
[2019-01-04 12:43:27] info at dreamtimeshop dot com
Hello and thank you.
Surprisingly, you are right! My complete code was as follows:
public static function _init() {
session_module_name('user');
session_set_save_handler(
array('ADODB_Session', 'sess_open'),
array('ADODB_Session', 'sess_close'),
array('ADODB_Session', 'sess_read'),
array('ADODB_Session', 'sess_write'),
array('ADODB_Session', 'sess_destroy'),
array('ADODB_Session', 'sess_gc')
);
register_shutdown_function('session_write_close');
}
It worked fine in all PHP versions, except when trying to upgrade to 7.2 or 7.3. After your comment,
I commented out the line "session_module_name('user');", and it works indeed!
Surely it makes no sense to call session_module_name exclusively without doing anything further.
Until now, this was always done just before calling "session_set_save_handler".
The current PHP documentation even indirectly mentions this as a prerequisite for using the database
for sessions. Quote:
session_set_save_handler() sets the user-level session storage functions which are used for storing
and retrieving data associated with a session. This is most useful when a storage method other than
those supplied by PHP sessions is preferred, e.g. storing the session data in a local database.
( http://php.net/manual/en/function.session-set-save-handler.php
)
According to this doc page, nothing has changed since version 7.0.
If it is not a bug, then this is a clear error in the documentation! Because in versions 7.2 and 7.3
"session_module_name" must not be used if you want to save sessions in the database.
------------------------------------------------------------------------
[2019-01-04 12:18:02] nikic@php.net
Yes, the exact version here is not really important, just that this was first introduced in 7.2.
But ... I don't really get what this bug is about. I'm not a session expert, but
isn't the "user" save handler set by calling session_set_save_handler()? What would
it even mean to use the "user" handler without calling session_set_save_handler()? I
expect that this was an intentional change to prevent exactly this kind of code.
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=77384
--
Edit this bug report at https://bugs.php.net/bug.php?id=77384&edit=1