|
php.net | support | documentation | report a bug | advanced search | search howto | statistics | random bug | login |
PatchesPull RequestsHistoryAllCommentsChangesGit/SVN commits
[2011-07-22 12:01 UTC] jesse dot hallam at gmail dot com
-Summary: session_regenerate_id fails after header sent even if
ini.use_cookies = 0
+Summary: session_regenerate_id fails after header sent even if
session.use_cookies = 0
[2011-07-22 12:01 UTC] jesse dot hallam at gmail dot com
[2011-08-29 21:19 UTC] bjori@php.net
-Status: Open
+Status: Closed
-Assigned To:
+Assigned To: bjori
[2011-08-29 21:19 UTC] bjori@php.net
[2011-08-29 21:20 UTC] bjori@php.net
[2012-04-18 09:49 UTC] laruence@php.net
[2012-07-24 23:40 UTC] rasmus@php.net
[2013-11-17 09:36 UTC] laruence@php.net
|
|||||||||||||||||||||||||||||||||||||
Copyright © 2001-2025 The PHP GroupAll rights reserved. |
Last updated: Mon Oct 27 20:00:01 2025 UTC |
Description: ------------ When unit testing session-related code in a CLI environment, appropriate PHP ini settings combined with passing false to session_cache_limiter can allow sessions to be started even if output has been already sent. Unfortunately, session_regenerate_id() fails unconditionally even when no cookie headers would have been sent: // session.c, session_regenerate_id if (SG(headers_sent)) { php_error_docref(NULL TSRMLS_CC, E_WARNING, "Cannot regenerate session id - headers already sent"); RETURN_FALSE; } // session.c, php_session_reset_id if (PS(use_cookies) && PS(send_cookie)) { php_session_send_cookie(TSRMLS_C); PS(send_cookie) = 0; } Is this just an oversight? Or intentional? Test script: --------------- <?php ini_set( 'session.use_cookies', 0 ); ini_set( 'session.use_only_cookies', 0 ); ini_set( 'session.use_trans_id', 1 ); // Don't send headers! session_cache_limiter( false ); echo 'test'; // Succeeds session_start(); // Fails session_regenerate_id(); ?> Expected result: ---------------- No warnings or errors. Output: test Actual result: -------------- testPHP Warning: session_regenerate_id(): Cannot regenerate session id - headers already sent in /home/jesse.hallam/tmp/session_test.php on line 15 PHP Stack trace: PHP 1. {main}() /home/jesse.hallam/tmp/session_test.php:0 PHP 2. session_regenerate_id() /home/jesse.hallam/tmp/session_test.php:15