Re: Solution for session_regenerate_id() issues

From: Date: Wed, 19 Mar 2014 18:17:48 +0000
Subject: Re: Solution for session_regenerate_id() issues
References: 1 2 3 4 5 6 7 8  Groups: php.internals 
Request: Send a blank email to internals+get-73304@lists.php.net to get a copy of this message
Hi Andrey, On Thu, Mar 20, 2014 at 12:22 AM, Andrey Andreev <narf@devilix.net> wrote: > On Wed, Mar 19, 2014 at 12:12 PM, Ferenc Kovacs <tyra3l@gmail.com> wrote: > >> If you choose "security" bug type, it's hidden. > > > > > > nope, security bug type only makes it send the bug mail to > security@php.net, > > only private bugs are protected from public access. > > that is something really error-prone, so I remember some discussion about > > changing that, and making new security bugs to be private by default, but > > AFAIK we never implemented that. > > Actually, somebody did implement it. > Turned out the issue I wanted to report is solved though ... it was > the regression with use_strict_mode in 5.5.3 and for some unknown > reason, Ubuntu is sticking exactly to that version. > > On topic: I understand the gains, Yasuo. > But I completely disagree that it's mandatory or that it is PHP's job > at all. If I tell PHP to delete something, I expect it to do so, > immediately. https://wiki.php.net/rfc/session_regenerate_id If you read my RFC, you'll see anyone can do that with session_start(['regenerate_id_expire'=>0']); or ini_set('session.regenerate_id_expire', 0); Regards, -- Yasuo Ohgaki yohgaki@ohgaki.net

« previous php.internals (#73304) next »