News:

CPG Release 1.6.29
During HTML5 upload, keep pseudo blank code 200 messages from triggering error condition
added Russian language
correct failure to use theme menu icons in album manager
minor vulnerabilities mitigation

Main Menu

SMF Session Verification Error on Logout Due to Serialization Handler Mismatch

Started by Lighting-Gallery, Yesterday at 07:58:23 PM

Previous topic - Next topic

0 Members and 1 Guest are viewing this topic.

Lighting-Gallery

I was attempting to set up a new Coppermine 1.6 installation bridged to our SMF 2.0.19 forum and hitting log out in CPG would always result in "Session verification failed.  Please try logging out and back in again, and then try again."  I tracked this down to a session serialization issue.  At some point SMF added @ini_set('session.serialize_handler', 'php_serialize') to their Load.php.  In CPG's smf20.inc.php _session_load() function it attempts to decode the session without specifying the handler.  This is usually going to be 'php' not 'php_serialize' and it will fail to deserialize the session.  As a result, it can't pass the session number value to SMF and it displays the error.  Adding the following to the start of _session_load() fixed the issue.

@ini_set('session.serialize_handler', 'php_serialize');
if (ini_get('session.serialize_handler') != 'php_serialize')
    @ini_set('session.serialize_handler', 'php');

I checked SMF 2.1 as well and although it does not display an error upon log out, CPG was still unable to deserialize the session data without it.  That might cause problems for anyone attempting to access SMF session variables within CPG.  It seems to me CPG should update the SMF bridge to deserialize using 'php_serialize'.