Tracker: Feature Requests

5 session.use_cookies = off breaks SquirrelMail - ID: 1518885
Last Update: Comment added ( tokul )

If session.use_cookies is set to off, SquirrelMail
1.4.7 and 1.5.2cvs logins fail.

Tested:
PHP 4.4.3cvs, 5.1.4, 4.3.10.
session.use_trans_sid = on
session.use_cookies = off

SquirrelMail scripts don't add session id to
redirection headers ('Location: some_url') and <meta>
refresh tags. PHP does not modify them too.

List of known broken scripts:
* src/redirect.php
* src/left_main.php (meta refresh)
* src/compose.php
* squirrelspell plugin (php does not rewrite Javascript
button action)
* src/download.php (See #1514631)


Tomas Kuliavas ( tokul ) - 2006-07-07 17:03

5

Open

None

Nobody/Anonymous

None

None

Public


Comments ( 4 )

Date: 2006-07-18 08:04
Sender: tokul

Logged In: YES
user_id=225877

Moving to feature requests. SquirrelMail 1.5.2 and 1.4.8
should not break when session.use_cookies = off. Scripts
turn session cookies on.

Feature is needed only for cookieless SquirrelMail.


Date: 2006-07-09 18:52
Sender: tokul

Logged In: YES
user_id=225877

----
if (!(bool)ini_get('session.use_cookies') ||
ini_get('session.use_cookies') == 'off') {
ini_set('session.use_cookies','1');
}
----
Hack turns on session cookies.

If we want to make SquirrelMail work with multiple logins in
one browser, we will need session.use_trans_sid and
session.use_cookies.


Date: 2006-07-09 09:57
Sender: kinkProject AdminAccepting Donations

Logged In: YES
user_id=285765

I vote for requiring session.use_cookies, since the
session.trans_sid option is and has always been an ugly
kludge; plus we require users to have cookies enabled anyway
so disabling the session cookie thing is not even useful.


Date: 2006-07-07 17:05
Sender: tokul

Logged In: YES
user_id=225877

Question: should we always add session id or test for
(!ini_get('session.use_cookies'))


Attached File

No Files Currently Attached

Change ( 1 )

Field Old Value Date By
data_type 350311 2006-07-18 08:04 tokul