Lighthouse has a new layout. Prefer the old one? Return to the old layout, and switch back any time from the link at the top of each page.

This project is archived and is in readonly mode.

Response and request objects don't use the same session

#1823

When a controller calls reset_session, the request, response, and controller's session objects should all be cleared. This is a current bug in rails HEAD @ (8761663a). It causes the following spec to fail:

http://gist.github.com/54773

Here's a test driven patch:

http://github.com/smtlaissezfair...

I've also attached a diff.

Reported by Scott Taylor · January 29th, 2009 @ 09:49 PM

State: resolved
Milestone: 2.x
Assigned to: josh josh
Importance: none

Activity

  1. Jonathan George
  2. Scott Taylor
    Scott Taylor

    This should be for the 2.3 milestone.

    January 29th, 2009 @ 10:58 PM

  3. Scott Taylor
    Scott Taylor
    • Tag set to bug, patch, session
    • Title changed from [Bug][Patch] response and request objects don't use the same session to [Bug] response and request objects don't use the same session

    January 29th, 2009 @ 11:30 PM

  4. Pratik
    Pratik
    • Assigned user set to josh
    • Title changed from [Bug] response and request objects don't use the same session to Response and request objects don't use the same session

    January 29th, 2009 @ 11:36 PM

  5. Repository
    Repository
    • State changed from new to resolved

    (from [2dedb5b03ab88a1c31068f71c8d4cad7c5a5d9ae]) Controller, response, and request should all refer to same session, even after a call to session_reset [#1823 Response and request objects don't use the same session state:resolved] Signed-off-by: Joshua Peek josh@joshpeek.com http://github.com/rails/rails/co...

    January 30th, 2009 @ 01:34 AM

  6. Scott Taylor
    Scott Taylor

    Thanks Josh.

    This is truly a new era in rails. I've never had a patch applied so quickly.

    Thanks again.

    January 30th, 2009 @ 02:13 AM

  7. Nolan Eakins
    Nolan Eakins

    Just curious, but does this patch happen to fix a bug I noticed last night on the 2.3 tag when using Mongrel where I'd use the cookie store, change the session, and it wouldn't get sent back to the client?

    Using Passenger and Thin I didn't have this problem.

    February 11th, 2009 @ 04:34 AM

  8. Scott Taylor
    Scott Taylor

    No. I have been experiencing exactly the same issue, and had thought that this would solve it (it didn't, though).

    As far as I can tell, mongrel calls the old rails deprecated cgi code, where thin uses the new rack adapter. The session bug doesn't occur when using any server with the rack adapter.

    I'm not sure why there isn't a big fat warning (Kernel#warn) when the old cgi module is clearly deprecated - it says so right there in the code.

    I think this is a pretty serious regression for 2.3.

    I'll run rdebug on mongrel_rails one more time to try to isolate it. Feel free to file a more proper bug report.

    February 11th, 2009 @ 04:42 AM

  9. Scott Taylor
    Scott Taylor

    Just to be clear, the bug is that the response session and the request session don't stay the same when using the cgi module. Here's a pastie of the debug session:

    http://gist.github.com/61838

    Notice that the same object is used for the session before calling reset_session, but afterwards the object is different.

    I'm working on a patch for this right now.

    February 11th, 2009 @ 06:52 AM

  10. Nolan Eakins
  11. Scott Taylor
    Scott Taylor

    Nolan,

    Great. Thanks. usually you can just refer to other tickets by ticket number: #1957 Sessions break in 2.3 with Mongrel

    I've got a patch in the works - the test suite is fully passing, but I know a few integration tests are missing as it doesn't quite seem to work in my project yet. Hopefully I can pull something together tonight.

    February 13th, 2009 @ 01:47 AM

  12. Nolan Eakins
    Nolan Eakins

    I'd be willing to apply your patch when you think it's ready to make sure it works. Seems like we're the only two who've run into this problem and that chose to be vocal about it.

    February 13th, 2009 @ 02:03 AM

  13. Josh Pencheon
    Josh Pencheon

    I'm having some problems with the session as well, but the other way round - it's working fine with mongrel (script/server) but doesn't work on Passenger.

    Calling reset_session in the controller doesn't seem to have any effect - I'm using the Authlogic gem, and am able to log in, but can't log out again!

    I'm afraid I'm going away tomorrow, so won't be around to follow this up for a few days...

    February 14th, 2009 @ 09:30 PM

  14. Scott Taylor
    Scott Taylor

    Josh Pencheon:

    Have you tried daemonizing mongrel? Does that affect the session state?

    February 16th, 2009 @ 01:25 AM

  15. Marius Mathiesen
    Marius Mathiesen

    I'm having the same problem as Josh Pencheon. What I'm trying to achieve is to issue two cookies upon login: the regular session cookie and an additional cookie that gets picked up by Varnished to avoid caching for authenticated users.

    As soon as I try setting two cookies to the user, only one of the cookies get sent in the header. The other one is sent in the response body and doesn't get picked up by the browser. That is, there's a "Set-Cookie..." in the actual contents, not in the header as it should be.

    Tried running the same app thru Mongrel (both daemonized and not), and it works like a charm.

    Kind of reminds me of the PHP days, when PHP would spit out a warning if one tries to send headers after the server has started sending the actual payload.

    February 25th, 2009 @ 09:57 AM

  16. Josh Pencheon
    Josh Pencheon

    Just to confirm, this seems to now be fixed with Rails 2.3.2 and Passenger 2.1.2. Thanks everyone. :-)

    March 16th, 2009 @ 07:24 PM