Skip to content

1.8.3: stale session cookie no longer 500s under the DB handler - #274

Merged
WebTigers merged 1 commit into
mainfrom
fix/stale-session-strict-mode
Sep 16, 2026
Merged

WebTigers merged 1 commit into
mainfrom
fix/stale-session-strict-mode

Conversation

@WebTigers

Copy link
Copy Markdown
Owner

1.8.2 fixed only the files handler; a live cPanel install uses the DB session handler, where the same stale cookie still 500'd (Zend/Session setId 'already started', via an unknown id PHP accepted because cPanel leaves use_strict_mode off). Enable session.use_strict_mode before start, keep the unreadable-files guard, retry once with a clean id on a start exception. Proven on host3 under BOTH handlers: a stale cookie now serves 200, not 500.

🤖 Generated with Claude Code

https://claude.ai/code/session_01L8p9pLJ3DFstG3xZuh2QgZ

1.8.2 covered only the files handler. cPanel leaves session.use_strict_mode off, so any unknown
client id is accepted; enable strict mode before start (PHP mints a fresh id), keep the
unreadable-files guard, and retry once on a start exception. Verified live under both handlers.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01L8p9pLJ3DFstG3xZuh2QgZ
@WebTigers
WebTigers merged commit 0cabaec into main Sep 16, 2026
14 checks passed
@WebTigers
WebTigers deleted the fix/stale-session-strict-mode branch September 16, 2026 09:08
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant