This project is archived and is in readonly mode.
Session cookie not sent with activerecord or memcache store in Rails 2.3.9
-
Mislav
Just published an unobtrusive fix for existing apps.
wget http://gist.github.com/570149.txt -O config/initializers/sessions_patch.rb -
Repository
- State changed from new to committed
(from [c6e33d30c1fe02e5729a269ab577967fb59a5e6c]) fix setting session cookie with activerecord and memcache store
Commit f8f3653 broke setting the session ID cookie for requests without 'HTTP_COOKIE' header
when using activerecord or memcache store. Integration tests didn't catch this because they
always set the HTTP_COOKIE header for mock requests, so now this is changed to only set the
header if there are cookies.[#5581 Session cookie not sent with activerecord or memcache store in Rails 2.3.9 state:committed]
Signed-off-by: Santiago Pastorino santiago@wyeworks.com
http://github.com/rails/rails/commit/c6e33d30c1fe02e5729a269ab57796... -
Josh Goebel
Is this going to result in a 2.3.10? Seems like a pretty serious issue that would affect a lot of people, no? Or has everyone moved on to Cookie store?
-
sowersb
I'd like to know too if there is a Rails 2.3.10 being planned. I'm using ActiveRecord as the session store in my app due to data sensitivity and this bug killed by 2.3.9 upgrade. There are still a lot of valid reasons for not using cookies to store sessions - data sensitivity and the bandwidth used to upload all session data on every request are the two biggest that I can think of.
-
Elise Huard
+1 it stopped us upgrading.
Mislav's fix will do us for now, but it doesn't make a great impression when an app just plum stops working on upgrade. We have an ActiveRecord session store.
-
jcapote (at gmail)
+1
Broke for me as well.
-
Brian Jensen
+1
Broken here as well. Mislavs patch has fixed it for now
-
Sébastien Grosjean - ZenCocoon
+1 Broken too. Mislav's patch temporary used as fix.
-
Mislav
Guys, I appreciate the +1s, but the core team were already aware and will incorporate this in the next release. If you want to nudge them to release sooner, write on the core mailing list! Thanks ;)
-
Repository
(from [ddf73603c1aeb6be3fd8619c7c0054d4cd6528c8]) Backport of documentation fixes:
cfc8c7ab54173c4f28776a69de23028d771f6e24 dfebdb1b033c033b7a39615a39d9d4ac3052e61d
[#5520 Online Rails 3 documentation has unescaped <script> tags] [#5537 Script tag in prototype_helper rdoc causing formatting issue in API] [#5581 Session cookie not sent with activerecord or memcache store in Rails 2.3.9] http://github.com/rails/rails/commit/ddf73603c1aeb6be3fd8619c7c0054...
-
Andrew White
Sorry about that - wrong ticket number in commit message