Skip to content

test(session): parity guard for regenerate mid-request (tina4-php#253) - #184

Merged
tina4stack merged 1 commit into
v3from
fix/session-regenerate-253
Sep 30, 2026
Merged

tina4stack merged 1 commit into
v3from
fix/session-regenerate-253

Conversation

@tina4stack

Copy link
Copy Markdown
Owner

Parity guard for tina4stack/tina4-php#253.

The upstream bug (PHP only)

Under tina4 serve (the socket server), PHP's native $_SESSION bridge re-emitted the session cookie only when the session was new at the start of the request. A mid-request session_regenerate_id() — the standard session-fixation defence on login — rotated the id after that check, so no Set-Cookie went out and the session was lost on the next request.

Why Python was already correct

$_SESSION / session_regenerate_id() are PHP language features with no analog in Python. Python's own session subsystem was never affected: core/server._stage_session_save emits a Set-Cookie on every request that saved a session, so a rotated id always reaches the client. A bug reported against one framework almost always exists in the others, so it earns a permanent regression test here too — if the serve path ever stopped propagating a rotated id, this goes red.

Proof

Wire-level test against a real child server (no mocks): request 1 writes the session and rotates its id via request.session.regenerate(); request 2 replays the rotated cookie and must find the same data under the new id. Verified green against a real file store and real Redis.

Cross-links tina4stack/tina4-php#253.

🤖 Generated with Claude Code

…kie (#253)

tina4stack/tina4-php#253 was a PHP-only defect in the native $_SESSION bridge
under the socket server: a mid-request session_regenerate_id() rotated the id
but never sent the new id to the client, so the session was lost next request.

Python's own session subsystem was never affected — core/server._stage_session_save
emits a Set-Cookie on every request that saved a session, so a rotated id always
reaches the client. A bug reported against one framework almost always exists in
the others, so it earns a permanent regression test here too: if the serve path
ever stopped propagating a rotated id, this goes red.

Proven on the wire against a REAL child server (no mocks), and verified green
against a real file store AND real Redis.

Co-Authored-By: Claude Opus 4.8 <[email protected]>
Co-Authored-By: Tina4 <[email protected]>
Signed-off-by: Andre van Zuydam <[email protected]>
@tina4stack
tina4stack merged commit 9cf7685 into v3 Sep 30, 2026
14 checks passed
@tina4stack
tina4stack deleted the fix/session-regenerate-253 branch September 30, 2026 13:02
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants