Problem/Motivation
The list of sessions on the session inspector page (via route session_inspector.manage) attempts to load the current session of the user.
This is because the SessionDeserializer defaults to using a SessionDeserializer::deserializePhP() method, which re-generates the session sid. It does prevent the user from losing their session as the session data is re-populated at the end of the method, but this is clearly flushing the data in the database.
This means that the current session sid is no longer present as it has been re-generated.
For the time being, the PHP ini setting can be changed from "php" to "php_binary" to change how this function works.
Steps to reproduce
Install the module.
Go to the session list page for the user.
Even with one session in place there is no "current" flag.
Proposed resolution
Look at the SessionDeserializer::deserializePhP() method and find a different way of deserialising the data for the "php" deserialization method.
Or, at least, ensure that the current session is not re-generated with a new session ID when running the SessionDeserializer::deserializePhP() method.
This method also needs to work with _other_ sessions in the session table, so we need to be careful not to copy one session onto another.
Remaining tasks
Write a test for this situation.
Issue fork session_inspector-3613732
Show commands
Start within a Git clone of the project using the version control instructions.
Or, if you do not have SSH keys set up on git.drupalcode.org:
Comments
Comment #2
philipnorton42 commentedComment #4
philipnorton42 commentedI believe this is working now. Even with old data the session inspection and delete interfaces work well with this change in place.
Comment #6
philipnorton42 commentedReleased in version 1.0.8.
https://www.drupal.org/project/session_inspector/releases/1.0.8