session.use_cookies = off
| From: | Hellekin O. Wild | Date: | Tue, 11 Dec 2001 00:30:46 +0000 |
| Subject: | session.use_cookies = off | ||
| Groups: | php.qa | ||
| Request: | Send a blank email to php-qa+get-4204@lists.php.net to get a copy of this message | ||
Dear QATs,
Please take the script at the URL below and perform tests on sessions to see if that report is correct on all settings among us. I'm confused about the sessions behaviors : did I miss something or must session_register() be called whatever the session_is_registered() result for the $var ?
I tested on 4.0.6 and 4.1.0RC5 with --enable-trans-sid.
session.use_cookies is set to 0 (= do not use session cookies).
session.save_handler = files
The test was made with 2 files going back and forth. Maybe that comes into play ?
See http://php.hellekin.com/test/test_session.phps (the other one is test_session2.php)
Current settings are displayed on the page (without a trailing "s") and on the /info.php as usual.
-> 4.0.6
-> register_globals = On
If you reload the page, a new session is set.
If you go to another page without SID set in the URL, a new session is set.
If you go to another page with SID set in the URL, session works normally but you must change globals and not the $HTTP_SESSION_VARS values directly.
-> register_globals = Off
If you reload the page, a new session is set.
If you go to another page without SID set in the URL, a new session is set.
If you go to another page with SID set in the URL, session works normally but you must change the $HTTP_SESSION_VARS values directly.
-> 4.1.0RC5
-> register_globals = On
If you reload the page, a new session is set.
If you go to another page without SID set in the URL, a new session is set.
If you go to another page with SID set in the URL, session works normally *after one page* and you can change either the globals or the corresponding values in $HTTP_SESSION_VARS (or $_SESSION).
-> register_globals = Off
If you reload the page, a new session is set.
If you go to another page without SID set in the URL, a new session is set.
If you go to another page with SID set in the URL, session works normally and you can change either the globals or the corresponding values in $HTTP_SESSION_VARS (or $_SESSION).
*
So, the conclusion is (with session.use_cookies = Off) :
- --enable-trans-sid doesn't behave correctly if session.use_cookies is Off. (From 4.0.6)
- There is a *new* bug in 4.1.0RC5 with register_globals = On that prevents session variables to be registered correctly on the first page after the session is registered.
- Sessions variable registration and changes though the $HTTP_SESSION_VARS is more coherent in 4.1.0RC5 than in 4.0.6.
*
Addendum for session behavior with session.use_cookies = On
-> 4.0.6
-> register_globals = On
If your variables are not changed, and you reload the page or go to another page without SID set in the URL, a new session is set.
If you set SID in the URL for the next page, session variables are registered correctly. Then you can reload the page or keep the URL without SID set and it will work. However, if you don't use SID, session is lost after 2 clicks.
-> register_globals = Off
Everything works fine.
-> 4.1.0RC5
Behaves the same as 4.0.6, for both settings of register_globals.
*
Conclusion :
- Sessions work fine with register_globals = Off
- register_globals = On make sessions behave strangely
- --enable-trans-sid doesn't prevent from using session cookies.
hellekin