Come together with the global Drupal community in Rotterdam, 28 Sept – 1 Oct 2026. Sessions, contribution, connection, and Early Bird savings until 8 June.
This is good, but to my opinion, the whole idea of "simulating" user session is a fail.
In this case, the session isn't started properly, and all functions called before swfupload session start would act incorrectly (assuming current user is anonymous).
In my opinion, the only way is to use custom session handler and specify 'session_inc' variable. But it requires changing settings.php file, which is not quite convenient. Maybe I'm missing something very obvious?
Comments
Comment #1
inktri commentedComment #2
whisk commentedThis is good, but to my opinion, the whole idea of "simulating" user session is a fail.
In this case, the session isn't started properly, and all functions called before swfupload session start would act incorrectly (assuming current user is anonymous).
In my opinion, the only way is to use custom session handler and specify 'session_inc' variable. But it requires changing settings.php file, which is not quite convenient. Maybe I'm missing something very obvious?
Comment #3
eugenmayer commentedCant understand the security issue - can you please rephrase and explain the attack vector?
Comment #4
skilip commentedThis issue has been created 3 yrs ago for 5.x-1.x-dev. I'm not sure this issue still applies.
Comment #5
eugenmayer commentedThats a point :)
Comment #6
skilip commentedThe Drupal 5 branch will not be longer supported
Comment #7
skilip commentedThe Drupal 5 branch will not be longer supported