Change record status: 
Project: 
Introduced in branch: 
11.2.x
Introduced in version: 
11.2.0
Description: 

In order to better defend against anonymous user session fixation attacks, Drupal enforces the PHP ini value session.use_strict_mode = 1.

The built-in SessionHandler class has been adapted to implement \SessionUpdateTimestampHandlerInterface in order to make it compatible with strict session mode.

Contrib and custom implementations of SessionHandler should implement \SessionUpdateTimestampHandlerInterface either by themselves or by reusing one of the following symfony base classes:

Impacts: 
Module developers