Can a POST request cause session getting destroyed, and if so how can it be prevented?

Viewed 157

It looks like sessions are getting destroyed when POST request is sent to an application that I am working on. The issue has been driving me insane - initially thinking there were issues with my business logic, then debugging the actually old Yii framework that the app makes use of. It turns out the issue happens even in vanilla PHP.

I have simplified things for testing purposes and here is the code. A script I call manually:

<?php
session_start();
$_SESSION['test'] = '123';

From an HTML file:

<form action="http://localhost/checker.php" method="post" target="_blank">
    <input type="text" name="PaRes" value="IDENTIFIED">
    <input type="submit" value="TEST POST">
</form>

Finally, the checker file:

<?php
session_start();
var_dump($_SESSION);

The reason why the POST request is done from a local HTML file using an absolute URL is that this needs to simulate the requirement in the real app's business logic (i.e. an external website making a post request to the app).

If I call the checker.php file manually with a GET method, the value of $_SESSION contains the set value and is displayed even after several minutes after it's been set.

If I call the checker.php file with a POST method, the value of $_SESSION is empty after 1-2 minutes from when the session was set.

Any ideas on what the issue might be?

PHP is 7.3.23 running on macOS. Below are ini settings for the session section:

session.auto_start  Off
session.cache_expire    180
session.cache_limiter   nocache
session.cookie_domain   no value
session.cookie_httponly no value
session.cookie_lifetime 0
session.cookie_path /
session.cookie_samesite no value
session.cookie_secure   0
session.gc_divisor  1000
session.gc_maxlifetime  1440
session.gc_probability  1
session.lazy_write  On
session.name    PHPSESSID
session.referer_check   no value
session.save_handler    files
session.save_path   no value
session.serialize_handler   php 
session.sid_bits_per_character  5   
session.sid_length  26
session.upload_progress.cleanup On
session.upload_progress.enabled On
session.upload_progress.freq    1%
session.upload_progress.min_freq    1
session.upload_progress.name    PHP_SESSION_UPLOAD_PROGRESS
session.upload_progress.prefix  upload_progress_
session.use_cookies 1
session.use_only_cookies    1
session.use_strict_mode 0
session.use_trans_sid   0

UPDATE:

It looks like this is only happening in Google Chrome. The session doesn't get destroyed when testing in Firefox. I have Chrome 87.0, cleared all browsing data, no extensions installed.

0 Answers
Related