Re: Solution for session_regenerate_id() issues
| From: | Yasuo Ohgaki | Date: | Wed, 19 Mar 2014 18:17:48 +0000 |
| Subject: | Re: Solution for session_regenerate_id() issues | ||
| References: | 1 2 3 4 5 6 7 8 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-73304@lists.php.net to get a copy of this message | ||
Hi Andrey,
On Thu, Mar 20, 2014 at 12:22 AM, Andrey Andreev <narf@devilix.net> wrote:
> On Wed, Mar 19, 2014 at 12:12 PM, Ferenc Kovacs <tyra3l@gmail.com> wrote:
> >> If you choose "security" bug type, it's hidden.
> >
> >
> > nope, security bug type only makes it send the bug mail to
> security@php.net,
> > only private bugs are protected from public access.
> > that is something really error-prone, so I remember some discussion about
> > changing that, and making new security bugs to be private by default, but
> > AFAIK we never implemented that.
>
> Actually, somebody did implement it.
> Turned out the issue I wanted to report is solved though ... it was
> the regression with use_strict_mode in 5.5.3 and for some unknown
> reason, Ubuntu is sticking exactly to that version.
>
> On topic: I understand the gains, Yasuo.
> But I completely disagree that it's mandatory or that it is PHP's job
> at all. If I tell PHP to delete something, I expect it to do so,
> immediately.
https://wiki.php.net/rfc/session_regenerate_id
If you read my RFC, you'll see anyone can do that with
session_start(['regenerate_id_expire'=>0']);
or
ini_set('session.regenerate_id_expire', 0);
Regards,
--
Yasuo Ohgaki
yohgaki@ohgaki.net