Doc #75883 [Com]: Documentation about name of a session should be less restrictive
| From: | robertworner786 at gmail dot com | Date: | Mon, 22 Mar 2021 11:37:14 +0000 |
| Subject: | Doc #75883 [Com]: Documentation about name of a session should be less restrictive | ||
| References: | 1 | Groups: | php.doc.bugs |
| Request: | Send a blank email to doc-bugs+get-18664@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=75883&edit=1
ID: 75883
Comment by: robertworner786 at gmail dot com
Reported by: thomas dot gerbet at enalean dot com
Summary: Documentation about name of a session should be less
restrictive
Status: Open
Type: Documentation Problem
Package: Session related
PHP Version: Irrelevant
Block user comment: N
Private report: N
New Comment:
Learn Web Design and Development -
HTML Tutorials for Beginners - Learn the fundamentals of the latest HTML5 markup language in simple
and easy steps and start building your own website. In this tutorial youâll learn html font
size, html code tag and more.
https://www.coderepublics.com/HTML/html-tutorial.php
https://www.coderepublics.com/HTML/html-font-tags.php
https://www.coderepublics.com/HTML/html-code-tag.php
https://www.coderepublics.com/HTML/html5-interview-questions.php
https://www.coderepublics.com/CSS/css-tutorial.php
Previous Comments:
------------------------------------------------------------------------
[2018-05-12 17:35:42] gadelat at gmail dot com
I believe this is due to legacy reasons. In past, PHP had register globals settings, which means
cookie names must meet PHP variable naming restrictions. This option no longer exists, so I think
this restriction should be elevated.
See https://harrybailey.com/2009/04/dots-arent-allowed-in-php-cookie-names/
------------------------------------------------------------------------
[2018-01-29 09:03:03] thomas dot gerbet at enalean dot com
Description:
------------
---
From manual page: http://www.php.net/function.session-name
---
Documentation mentions that only alphanum chars should be used as a session name since the name can
be used in URLs and cookies.
This is a bit too restrictive and prevent for example to use the cookie prefixes restriction [1]
browser feature.
According to RFC1738 and RFC3986 the characters $-_.+!*'(), should also be safe to use in URLs
and it seems that RFC6265 does not add more limitations for cookies. These characters can probably
be added to the documentation as "safe to use" as the name of a session.
[1] https://tools.ietf.org/html/draft-west-cookie-prefixes
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=75883&edit=1