mirror of
https://github.com/php/php-src.git
synced 2026-04-25 08:58:28 +02:00
MFH: fix bug #32944 (Disabling session.use_cookies doesn't prevent reading session cookies)
This commit is contained in:
@@ -18,6 +18,8 @@ PHP NEWS
|
||||
(jwozniak23 at poczta dot onet dot pl, Tony).
|
||||
- Fixed bug #32956 (mysql_bind_result() doesn't support MYSQL_TYPE_NULL). (Georg)
|
||||
- Fixed bug #32947 (Incorrect option for mysqli default password). (Georg)
|
||||
- Fixed bug #32944 (Disabling session.use_cookies doesn't prevent reading
|
||||
session cookies). (Jani, Tony)
|
||||
- Fixed bug #32936 (http redirects URLs are not checked for control chars). (Ilia)
|
||||
- Fixed bug #32932 (Oracle LDAP: ldap_get_entries(), invalid pointer). (Jani)
|
||||
- Fixed bug #32930 (class extending DOMDocument doesn't clone properly). (Rob)
|
||||
|
||||
@@ -1134,7 +1134,7 @@ PHPAPI void php_session_start(TSRMLS_D)
|
||||
*/
|
||||
|
||||
if (!PS(id)) {
|
||||
if (zend_hash_find(&EG(symbol_table), "_COOKIE",
|
||||
if (PS(use_cookies) && zend_hash_find(&EG(symbol_table), "_COOKIE",
|
||||
sizeof("_COOKIE"), (void **) &data) == SUCCESS &&
|
||||
Z_TYPE_PP(data) == IS_ARRAY &&
|
||||
zend_hash_find(Z_ARRVAL_PP(data), PS(session_name),
|
||||
|
||||
Reference in New Issue
Block a user