Specifics of your environment
Using SimpleSAMLphp 2.4.10-slim as an SP as documented, using default PHP sessions.
Describe the bug
The \SimpleSAML\Auth\Simple constructor creates a session even if one doesn't exist from before. This is not necessary if the class is only used to check isAuthenticated(), and causes unnecessary session files to be written on the host.
To Reproduce
$auth = new \SimpleSAML\Auth\Simple('default-sp');
if (!$auth->isAuthenticated()) {
print('<a href="/login">Login</a>');
}
With the default SimpleSAMLphp configuration.
When visiting with a clean browser (private tab), a cookie SimpleSAML is set.
Expected behavior
No cookie was set because we didn't do anything, and there was no pre-existing session.
Additional context
The documentation suggests that the session is activated upon calling isAuthenticated(), but the session is already created in the constructor, and isAuthenticated() does nothing that can trigger a session to be created.
I didn't call \SimpleSAML\Session::getSessionFromRequest()->cleanup();, as there is no previous session it wouldn't have done anything.
Specifics of your environment
Using SimpleSAMLphp 2.4.10-slim as an SP as documented, using default PHP sessions.
Describe the bug
The
\SimpleSAML\Auth\Simpleconstructor creates a session even if one doesn't exist from before. This is not necessary if the class is only used to checkisAuthenticated(), and causes unnecessary session files to be written on the host.To Reproduce
With the default SimpleSAMLphp configuration.
When visiting with a clean browser (private tab), a cookie
SimpleSAMLis set.Expected behavior
No cookie was set because we didn't do anything, and there was no pre-existing session.
Additional context
The documentation suggests that the session is activated upon calling
isAuthenticated(), but the session is already created in the constructor, andisAuthenticated()does nothing that can trigger a session to be created.I didn't call
\SimpleSAML\Session::getSessionFromRequest()->cleanup();, as there is no previous session it wouldn't have done anything.