Repository navigation
system/request: guard session_start() with session_status() - #500
Merged
Merged
Conversation
Session::__construct() calls session_start() unconditionally. Instantiating the class when a session is already active makes PHP emit: Notice: session_start(): Ignoring session_start() because a session is already active This happens in piler's own SSO entry point: webui/sso.php starts a session three times in a single request - explicitly at line 2, through config.php:405 at line 6, and again at line 10. Checking session_status() first makes the constructor idempotent. On a fresh request nothing changes: session_status() returns PHP_SESSION_NONE and session_start() runs exactly as before.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Session::__construct()inwebui/system/request.phpcallssession_start()unconditionally:
When the class is instantiated while a session is already active, PHP logs:
The file effectively warns about itself, which is confusing when tracking down
session problems.
This happens in piler's own SSO entry point.
webui/sso.phpstarts a sessionthree times in a single request:
Guarding with
session_status()makes the constructor idempotent. On a freshrequest nothing changes:
session_status()returnsPHP_SESSION_NONEandsession_start()runs exactly as before.Environment: piler 1.4.9, PHP 8.5, Ubuntu 26.04.