Lighthouse has a new layout. Prefer the old one? Return to the old layout, and switch back any time from the link at the top of each page.

This project is archived and is in readonly mode.

Session cookie not sent with activerecord or memcache store in Rails 2.3.9

#5581

Commit f8f3653 broke setting the session ID cookie for requests without 'HTTP_COOKIE' header
when using activerecord or memcache store. Integration tests didn't catch this because they
always set the HTTP_COOKIE header for mock requests, so now this is changed to only set the
header if there are cookies.

Fixed by b773d86 in my fork

Reported by Mislav · September 8th, 2010 @ 02:27 PM

State: committed
Milestone: none
Assigned to: nobody
Importance: Low

Activity

  1. Mislav
    Mislav

    Just published an unobtrusive fix for existing apps.

    wget http://gist.github.com/570149.txt -O config/initializers/sessions_patch.rb
    

    September 8th, 2010 @ 03:00 PM

  2. Repository
    Repository
    • State changed from new to committed

    (from [c6e33d30c1fe02e5729a269ab577967fb59a5e6c]) fix setting session cookie with activerecord and memcache store

    Commit f8f3653 broke setting the session ID cookie for requests without 'HTTP_COOKIE' header
    when using activerecord or memcache store. Integration tests didn't catch this because they
    always set the HTTP_COOKIE header for mock requests, so now this is changed to only set the
    header if there are cookies.

    [#5581 Session cookie not sent with activerecord or memcache store in Rails 2.3.9 state:committed]

    Signed-off-by: Santiago Pastorino santiago@wyeworks.com
    http://github.com/rails/rails/commit/c6e33d30c1fe02e5729a269ab57796...

    September 8th, 2010 @ 05:03 PM

  3. Josh Goebel
    Josh Goebel

    Is this going to result in a 2.3.10? Seems like a pretty serious issue that would affect a lot of people, no? Or has everyone moved on to Cookie store?

    September 8th, 2010 @ 06:11 PM

  4. sowersb
    sowersb

    I'd like to know too if there is a Rails 2.3.10 being planned. I'm using ActiveRecord as the session store in my app due to data sensitivity and this bug killed by 2.3.9 upgrade. There are still a lot of valid reasons for not using cookies to store sessions - data sensitivity and the bandwidth used to upload all session data on every request are the two biggest that I can think of.

    September 8th, 2010 @ 09:14 PM

  5. Michael Koziarski
    Michael Koziarski
    • Importance changed from to Low

    Yes, this justifies a 2.3.10 release

    September 8th, 2010 @ 09:49 PM

  6. Elise Huard
    Elise Huard

    +1 it stopped us upgrading.

    Mislav's fix will do us for now, but it doesn't make a great impression when an app just plum stops working on upgrade. We have an ActiveRecord session store.

    September 13th, 2010 @ 04:05 PM

  7. jcapote (at gmail)
  8. Brian Jensen
    Brian Jensen

    +1

    Broken here as well. Mislavs patch has fixed it for now

    October 8th, 2010 @ 09:27 AM

  9. Sébastien Grosjean - ZenCocoon
    Sébastien Grosjean - ZenCocoon

    +1 Broken too. Mislav's patch temporary used as fix.

    October 13th, 2010 @ 01:40 PM

  10. Mislav
    Mislav

    Guys, I appreciate the +1s, but the core team were already aware and will incorporate this in the next release. If you want to nudge them to release sooner, write on the core mailing list! Thanks ;)

    October 13th, 2010 @ 05:27 PM

  11. Repository
  12. Andrew White
    Andrew White

    Sorry about that - wrong ticket number in commit message

    October 29th, 2010 @ 07:32 AM

  13. bingbing