diff --git a/CHANGELOG.md b/CHANGELOG.md index 6af09c2..113a854 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -4,6 +4,7 @@ - Enh #86: Remove `yiisoft/cookies` dependency (@vjik) - Bug #86: `NullSession::getCookieParameters()` now returns proper cookie parameters instead of an empty array (@vjik) +- Bug #25: Fix reusing the previous session ID in `Session::open()` in long-running workers (@klsoft-web) ## 3.0.2 August 26, 2026 diff --git a/src/Session.php b/src/Session.php index c272959..9f43e7e 100644 --- a/src/Session.php +++ b/src/Session.php @@ -92,9 +92,7 @@ public function open(): void return; } - if ($this->sessionId !== null) { - session_id($this->sessionId); - } + session_id($this->sessionId ?? ''); try { session_start($this->options); diff --git a/tests/SessionTest.php b/tests/SessionTest.php index 5cb781a..a33988f 100644 --- a/tests/SessionTest.php +++ b/tests/SessionTest.php @@ -94,6 +94,19 @@ public function testRegenerateIdOpensInactiveSession(): void self::assertNotEquals($id, $session->getId()); } + public function testOpenDoesNotReuseIdOfClosedSession(): void + { + $firstSession = new Session(); + $firstSession->open(); + $firstId = $firstSession->getId(); + $firstSession->close(); + + $secondSession = new Session(); + $secondSession->open(); + + self::assertNotSame($firstId, $secondSession->getId()); + } + public function testDiscard(): void { $session = $this->getSession();