php.net |  support |  documentation |  report a bug |  advanced search |  search howto |  statistics |  random bug |  login
Bug #74892 Url Rewriting (trans_sid) not working on urls that start with #
Submitted: 2017-07-10 14:30 UTC Modified: 2017-07-10 15:18 UTC
From: drchuck at gmail dot com Assigned:
Status: Closed Package: Session related
PHP Version: 7.1.7 OS: Mac OS/X
Private report: No CVE-ID:
 [2017-07-10 14:30 UTC] drchuck at gmail dot com
Description:
------------
When there is a URL that starts with "#" in an anchor tag, PHP 7.1.1 still adds the PHPSESSID parameter like this:

<p><a href="index.php?PHPSESSID=a17309afea8f2791078fc046cce5fa56">Click This Anchor Tag!</a></p>
<p><a href="#place/?PHPSESSID=a17309afea8f2791078fc046cce5fa56">Internal link</a></p>
<p>Our Session ID is: a17309afea8f2791078fc046cce5fa56</p>
<p>Our PHP Version is: 7.1.1</p>

Test script:
---------------
<?php
    ini_set('session.use_cookies', '0');
    ini_set('session.use_only_cookies',0);
    ini_set('session.use_trans_sid',1);
    session_start();
?>
<p><a href="index.php">Click This Anchor Tag!</a></p>
<p><a href="#place">Internal link</a></p>
<p>Our Session ID is: <?= session_id() ?></p>
<p>Our PHP Version is: <?= phpversion() ?></p>

Expected result:
----------------
<p><a href="index.php?PHPSESSID=aec2a7538bfe295d6a6c9ff70c42f8eb">Click This Anchor Tag!</a></p>
<p><a href="#place">Internal link</a></p>
<p>Our Session ID is: aec2a7538bfe295d6a6c9ff70c42f8eb</p>
<p>Our PHP Version is: 5.6.28</p>

This is the output from the script on 5.6.28.  Note that '#place" does not get the session applied.

Actual result:
--------------
<p><a href="index.php?PHPSESSID=a17309afea8f2791078fc046cce5fa56">Click This Anchor Tag!</a></p>
<p><a href="#place/?PHPSESSID=a17309afea8f2791078fc046cce5fa56">Internal link</a></p>
<p>Our Session ID is: a17309afea8f2791078fc046cce5fa56</p>
<p>Our PHP Version is: 7.1.1</p>

This is the output from 7.1.1 (sorry I don't have easy access to 7.1.7)

Patches

Add a Patch

Pull Requests

Pull requests:

Add a Pull Request

History

AllCommentsChangesGit/SVN commitsRelated reports
 [2017-07-10 15:18 UTC] requinix@php.net
-Status: Open +Status: Verified
 [2017-07-10 15:18 UTC] requinix@php.net
Affects 7.1+ https://3v4l.org/U96sK
 [2017-07-11 18:54 UTC] andrew dot nester dot dev at gmail dot com
Thanks for reporting the issue! I've just sent PR fixing this.
 [2017-07-18 19:23 UTC] nikic@php.net
Automatic comment on behalf of andrew.nester.dev@gmail.com
Revision: http://git.php.net/?p=php-src.git;a=commit;h=6c32d271d238a18cfc19d98877cdead1ab38f417
Log: Fixed #74892 - Fixed URL rewriting for urls started with #
 [2017-07-18 19:23 UTC] nikic@php.net
-Status: Verified +Status: Closed
 
PHP Copyright © 2001-2017 The PHP Group
All rights reserved.
Last updated: Tue Aug 29 15:01:52 2017 UTC