Re: [RFC] [Discussion] Deprecate GET/POST sessions
| From: | Kamil Tekiela | Date: | Fri, 05 Apr 2024 19:05:12 +0000 |
| Subject: | Re: [RFC] [Discussion] Deprecate GET/POST sessions | ||
| References: | 1 2 3 4 5 6 7 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-122980@lists.php.net to get a copy of this message | ||
>1. In session_start(), it is possible to override ini settings like that:
>
>```php
>session_start([ 'use_cookies' => '1', 'use_only_cookies' =>
>'1', 'referer_check' => '' ]);
>```
>
>The relevant options should also be deprecated in that context.
Yes, they are. You can see that in my draft PR
https://github.com/php/php-src/pull/13578
> 2. A clarification: Suppose that I have
session.use_only_cookie =
> 1 in my ini file (no deprecation warning), and I call
> ini_set("session.use_only_cookie", "1") in my
> code (no-op). Will the ini_set(...) invocation trigger a deprecation
> warning?
As mentioned in the RFC, only changing the option to the deprecated
value triggers the deprecation. You can verify this using my draft PR.
Similarly, if your INI file triggers a deprecations due to for example
session.use_only_cookie=0 and then in your PHP file you change it
using ini_set("session.use_only_cookie", "1") or using the argument to
session_start(), it will only trigger the deprecation during startup
and not during runtime of the script.