Skip to content

1.8.2: a stale session cookie starts a fresh session instead of a 500 - #273

Merged
WebTigers merged 1 commit into
mainfrom
fix/stale-session-id
Sep 16, 2026
Merged

WebTigers merged 1 commit into
mainfrom
fix/stale-session-id

Conversation

@WebTigers

Copy link
Copy Markdown
Owner

cPanel's shared session dir after an account is deleted and recreated: the browser's PHPSESSID names a file owned by the old uid; session_start() fails; PHP defines SID even then, so Zend_Session cannot retry. Check the presented id's file BEFORE starting; fresh id when unreadable. Found in the second outside install round (TIGER-138). Proven on host3: the recreated site 500s on 1.8.1 with such a cookie.

🤖 Generated with Claude Code

https://claude.ai/code/session_01L8p9pLJ3DFstG3xZuh2QgZ

…n instead of a 500

cPanel's shared session dir after an account is recreated: the file belongs to the old uid.
PHP defines SID even on a failed session_start(), so the check must come first.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01L8p9pLJ3DFstG3xZuh2QgZ
@WebTigers
WebTigers merged commit 9b337be into main Sep 16, 2026
14 checks passed
@WebTigers
WebTigers deleted the fix/stale-session-id branch September 16, 2026 08:45
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant