Sitelet https://github.com/phpredis/phpredis/issues/1657#top
Skip to content

PHP Session Handler doesn't support non TCP schemes like TLS. #1657

Description

@acollard

The redis_session.c code uses only the host parameter from php_url_parse_ex, resulting in the scheme being removed. The Redis connection then defaults to tcp.

redis_sock = redis_sock_create(ZSTR_VAL(url->host), ZSTR_LEN(url->host), url->port, timeout, read_timeout, persistent, persistent_id, retry_interval);

Connecting with the Redis object directly works fine using TLS.

Expected behaviour

PHP session handler should support TLS and the code should not filter out the scheme when creating the connection.

Actual behaviour

Connecting with tls://... doesn't work for the session handler. The error is "read error on connection to mydomain.redis.cache.windows.net:6380".

I'm seeing this behaviour on

  • OS: Ubuntu 18.04
  • Redis: Azure Cache for Redis
  • PHP: 7.3
  • phpredis: 5.0.2

Steps to reproduce, backtrace or example script

ini_set('session.save_handler', 'redis');
ini_set('session.save_path', 'tls://mydomain.redis.cache.windows.net:6380?auth=someauthstring');
session_start(); // Will throw RedisException

I've checked

  • There is no similar issue from other users
  • Issue isn't fixed in develop branch

Workaround

As a temporary workaround we've just implemented our own SessionHandler which uses Redis object directly.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions