php.net |  support |  documentation |  report a bug |  advanced search |  search howto |  statistics |  random bug |  login
Doc Bug #64058 Warn about register_globals
Submitted: 2013-01-23 20:14 UTC Modified: 2013-01-25 09:41 UTC
From: ph57 at brisk dot org dot uk Assigned: krakjoe (profile)
Status: Closed Package: Documentation problem
PHP Version: 5.3.21 OS: n/r
Private report: No CVE-ID: None
Welcome back! If you're the original bug submitter, here's where you can edit the bug or add additional notes.
If you forgot your password, you can retrieve your password here.
Password:
Status:
Package:
Bug Type:
Summary:
From: ph57 at brisk dot org dot uk
New email:
PHP Version: OS:

 

 [2013-01-23 20:14 UTC] ph57 at brisk dot org dot uk
Description:
------------
---
From manual page: http://uk1.php.net/manual/en/session.examples.basic.php
---
Please can we have a very prominent WARNING, in the introduction to session, along the lines of:-

WARNING: if register_globals is set ON, then any key you use in $_SESSION will be a reference to a global variable of the same name. This will cause your session vasriables to change unexpectedly if you accidentally use a key that happens to match the name of an existing global variable.


Patches

Pull Requests

History

AllCommentsChangesGit/SVN commitsRelated reports
 [2013-01-24 12:35 UTC] krakjoe@php.net
http://php.net/manual/en/ini.core.php#ini.register-globals

register_globals is a deprecated feature in the version of PHP you are reported 
to be using. It is removed in the final release after it.

Therefore there is no need to include any more information than is included in 
the manual page I have linked to.
 [2013-01-24 12:57 UTC] krakjoe@php.net
-Status: Open +Status: Closed -Assigned To: +Assigned To: krakjoe
 [2013-01-24 13:45 UTC] ph57 at brisk dot org dot uk
It is a pity that, even when serious deficiencies are drawn to your attention, you arrogantly refuse to correct them. The fact that register_globals is a deprecated feature is not relevant. The fact is there is absolutely no mention of register_globals, or its appalling side-effects, in the SESSION documentation. So it is possible for someone, like myself, to read the whole of the SESSION documentation, and use it, whilst remaining completely ignorant of this underlying disaster.

I simply askled you to warn people. You refuse. That is a very bad decision. I won't bother to try to help you improve in future. Goodbye.
 [2013-01-24 16:47 UTC] philip@php.net
I thought we already mentioned this, or do somewhere else. Does someone else 
remember? There are plenty of PHP 5.3 (and below) users out there. We document PHP 
5.1 and above.
 [2013-01-24 19:20 UTC] ph57 at brisk dot org dot uk
Actually it doesn't mention the linkage between $_SESSION keys and global variables anywhere in the SESSION documentation (although I think I did find a posting by someone somewhere in there that obliquely alerted me to the issue, but I don't think one should have to read all the postings which are often long or old). Yesterday I hadn't even heard of register_globals (why read about deprecated features?). Now I know what it is, having spent the whole of yesterday afternoon investigating why my session vars were changing under my feet. I wouldn't have made this mistake if there had been a mention of this issue in the SESSION documentation.
 [2013-01-25 07:37 UTC] krakjoe@php.net
Automatic comment from SVN on behalf of krakjoe
Revision: http://svn.php.net/viewvc/?view=revision&revision=329295
Log: in response to bug #64058, a warning is apparently appropriate
 [2013-01-25 07:39 UTC] krakjoe@php.net
Please accept my apologies, I am new to the doc team and did not realize we 
documented versions of PHP that are so old
 [2013-01-25 07:39 UTC] krakjoe@php.net
-Status: Closed +Status: Re-Opened
 [2013-01-25 07:44 UTC] krakjoe@php.net
This bug has been fixed in the documentation's XML sources. Since the
online and downloadable versions of the documentation need some time
to get updated, we would like to ask you to be a bit patient.

Thank you for the report, and for helping us make our documentation better.

Please accept my apologies; I am new to the documentation team and simply did not 
realize that it would be acceptable to do as you asked ( to document what I saw 
as a deprecated feature ). I have since been corrected and I have updated the 
documentation with an appropriate warning.

I hope you can find your way to reporting more bugs should you find them, I 
assure you they are never met with arrogance, only a willingness to help out in 
our spare time.
 [2013-01-25 07:44 UTC] krakjoe@php.net
-Status: Re-Opened +Status: Closed
 [2013-01-25 09:41 UTC] ph57 at brisk dot org dot uk
Jolly good. Thanks a lot.
 [2013-01-25 10:37 UTC] krakjoe@php.net
Automatic comment from SVN on behalf of krakjoe
Revision: http://svn.php.net/viewvc/?view=revision&revision=329296
Log: correct response to #64058
 
PHP Copyright © 2001-2026 The PHP Group
All rights reserved.
Last updated: Tue Oct 06 23:00:02 2026 UTC