Skip to content

system/request: guard session_start() with session_status() - #500

Merged
jsuto merged 1 commit into
jsuto:masterfrom
krzsztf1:fix-session-start-guard
Oct 7, 2026
Merged

jsuto merged 1 commit into
jsuto:masterfrom
krzsztf1:fix-session-start-guard

Conversation

@krzsztf1

Copy link
Copy Markdown
Contributor

Session::__construct() in webui/system/request.php calls session_start()
unconditionally:

class Session {
   public function __construct() {
      session_start();
   }

When the class is instantiated while a session is already active, PHP logs:

PHP Notice: session_start(): Ignoring session_start() because a session is
already active (started from /var/piler/www/system/request.php on line 30)
in /var/piler/www/system/request.php on line 30

The file effectively warns about itself, which is confusing when tracking down
session problems.

This happens in piler's own SSO entry point. webui/sso.php starts a session
three times in a single request:

session_start();                 // line 2
require_once("config.php");      // line 6 -> config.php:405 does new Session()
$session = new Session();        // line 10

Guarding with session_status() makes the constructor idempotent. On a fresh
request nothing changes: session_status() returns PHP_SESSION_NONE and
session_start() runs exactly as before.

Environment: piler 1.4.9, PHP 8.5, Ubuntu 26.04.

Session::__construct() calls session_start() unconditionally. Instantiating
the class when a session is already active makes PHP emit:

  Notice: session_start(): Ignoring session_start() because a session is
  already active

This happens in piler's own SSO entry point: webui/sso.php starts a session
three times in a single request - explicitly at line 2, through config.php:405
at line 6, and again at line 10.

Checking session_status() first makes the constructor idempotent. On a fresh
request nothing changes: session_status() returns PHP_SESSION_NONE and
session_start() runs exactly as before.

@jsuto jsuto left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thank you!

@jsuto
jsuto merged commit 40d97e3 into jsuto:master Oct 7, 2026
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants