Uploaded image for project: 'Moodle'
  1. Moodle
  2. MDL-46561

\core\session\manager::session_exists() does not check sessions table

    XMLWordPrintable

    Details

    • Type: Improvement
    • Status: Closed
    • Priority: Minor
    • Resolution: Fixed
    • Affects Version/s: 2.6.2, 2.7
    • Fix Version/s: 2.8
    • Component/s: General
    • Labels:

      Description

      The \core\session\manager::session_exists() phpdocs says that it is not supposed to check the sessions table for existence of sid, but the WS code expects it anyway.

      I suppose it should be changed to first verify the db record for session exists and only if yes try to lookup the sid in session backend.

      This may be a security issue because the session gc may not always work properly - see MDL-46552

        Attachments

          Issue Links

            Activity

              People

              Assignee:
              skodak Petr Skoda
              Reporter:
              skodak Petr Skoda
              Peer reviewer:
              Frédéric Massart
              Integrator:
              Dan Poltawski
              Tester:
              Simey Lameze
              Participants:
              Component watchers:
              Adrian Greeve, Jake Dallimore, Mathew May, Mihail Geshoski, Peter Dias
              Votes:
              0 Vote for this issue
              Watchers:
              3 Start watching this issue

                Dates

                Created:
                Updated:
                Resolved:
                Fix Release Date:
                10/Nov/14