Session API allows to configure the cookie lifetime by changing the value of "session_api_cookie_expire_time" variable. This variable allows -1 as value, which will make the cookie to expire when the session ends.
By other hand FlagNonGlobalCookieStorage uses a different lifetime based on "session.cookie_lifetime" and "session.gc_maxlifetime". This mismatch could potentially cause that users will have values in the "flags" cookie while not having records in the "flagging" table related to his/her sid.

CommentFileSizeAuthor
#1 2399421-1-cookie-lifetime.patch1.15 KBcapuleto

Comments

capuleto’s picture

StatusFileSize
new1.15 KB
voron’s picture

thanks for the path
it fixed for me anonymous flagging on pantheon

capuleto’s picture

Status: Active » Needs review
ivnish’s picture

Status: Needs review » Closed (outdated)

Drupal 7 is EOL. Issue will be closed, but patches are still here