Doc #75883 [Com]: Documentation about name of a session should be less restrictive

From: Date: Tue, 02 Mar 2021 04:26:18 +0000
Subject: Doc #75883 [Com]: Documentation about name of a session should be less restrictive
References: 1  Groups: php.doc.bugs 
Request: Send a blank email to doc-bugs+get-18610@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=75883&edit=1 ID: 75883 Comment by: roanparker158 at gmail dot com Reported by: thomas dot gerbet at enalean dot com Summary: Documentation about name of a session should be less restrictive Status: Open Type: Documentation Problem Package: Session related PHP Version: Irrelevant Block user comment: N Private report: N New Comment: We have been Partner with Canon since last 19yrs. FotoFlux as a firm is a 27yrs old company in New York. We have a staff of almost 30 employees including California. https://canonsetup-canon.com/ijsetup/ Previous Comments: ------------------------------------------------------------------------ [2018-05-12 17:35:42] gadelat at gmail dot com I believe this is due to legacy reasons. In past, PHP had register globals settings, which means cookie names must meet PHP variable naming restrictions. This option no longer exists, so I think this restriction should be elevated. See https://harrybailey.com/2009/04/dots-arent-allowed-in-php-cookie-names/ ------------------------------------------------------------------------ [2018-01-29 09:03:03] thomas dot gerbet at enalean dot com Description: ------------ --- From manual page: http://www.php.net/function.session-name --- Documentation mentions that only alphanum chars should be used as a session name since the name can be used in URLs and cookies. This is a bit too restrictive and prevent for example to use the cookie prefixes restriction [1] browser feature. According to RFC1738 and RFC3986 the characters $-_.+!*'(), should also be safe to use in URLs and it seems that RFC6265 does not add more limitations for cookies. These characters can probably be added to the documentation as "safe to use" as the name of a session. [1] https://tools.ietf.org/html/draft-west-cookie-prefixes ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=75883&edit=1

« previous php.doc.bugs (#18610) next »