#49432 [Com]: $_SESSION cannot store objects and resources
| From: | preinheimer at gmail dot com | Date: | Tue, 01 Sep 2009 19:20:31 +0000 |
| Subject: | #49432 [Com]: $_SESSION cannot store objects and resources | ||
| References: | 1 | Groups: | php.doc.bugs |
| Request: | Send a blank email to doc-bugs+get-2706@lists.php.net to get a copy of this message | ||
ID: 49432
Comment by: preinheimer at gmail dot com
Reported By: jost dot boekemeier at googlemail dot com
Status: Open
Bug Type: Documentation problem
Operating System: Any
PHP Version: Irrelevant
New Comment:
Objects can in fact be stored in sessions. They are serialized for
storage, the __sleep() and __wakeup() magic methods have been created to
add functionality to the process.
Clarification regarding resources could be added to the current note on
references to make things more clear.
Previous Comments:
------------------------------------------------------------------------
[2009-09-01 17:14:26] jost dot boekemeier at googlemail dot com
Description:
------------
The session documentation does not make it clear that PHP cannot
(logically and in its current implementation) store objects or
resources.
This lack of specification makes it hard for external libraries to
respond to bug reports like this one:
http://bugs.php.net/bug.php?id=13840&edit=1.
(BTW: In bug#13840 Mr. Holzgreve states that "php sessions can store
every PHP data type including objects". This is clearly WRONG and shows
that even PHP devs don't understand the PHP scripting language.)
We've had a similar bug report for the PHP/Java Bridge. This person
wanted to store a Java object into the session.
Please add the following to the _SESSION documentation:
"PHP sessions can only store PHP /values/, for example exact or inexact
numbers. They *cannot* store any other PHP data types, including
resources and objects. If you want to store complex data in the session,
serialize the data into a string value first."
Please note that I have filed this as a documentation bug, not a bug in
the PHP implementation.
Reproduce code:
---------------
<?php
class X {
var $destroyed;
function __sleep() { echo "s"; if ($this->destroyed) { echo("\nerror:
destroyed"); sleep (10); exit(1);} /*not reached*/ }
function __destruct() { echo "d"; $this->destroyed = true; }
function __construct() { echo "c"; $this->destroyed = false; }
}
session_start();
$x= new X();
$_SESSION["X"]=$x;
?>
Expected result:
----------------
The above script should not call __destruct() before __sleep();
Actual result:
--------------
__destruct() is called before __sleep()
------------------------------------------------------------------------
--
Edit this bug report at http://bugs.php.net/?id=49432&edit=1