Skip to content

Auth\Simple class creates unnecessary sessions #2684

Description

@jornane

Specifics of your environment

Using SimpleSAMLphp 2.4.10-slim as an SP as documented, using default PHP sessions.

Describe the bug

The \SimpleSAML\Auth\Simple constructor creates a session even if one doesn't exist from before. This is not necessary if the class is only used to check isAuthenticated(), and causes unnecessary session files to be written on the host.

To Reproduce

$auth = new \SimpleSAML\Auth\Simple('default-sp');
if (!$auth->isAuthenticated()) {
    print('<a href="/login">Login</a>');
}

With the default SimpleSAMLphp configuration.
When visiting with a clean browser (private tab), a cookie SimpleSAML is set.

Expected behavior

No cookie was set because we didn't do anything, and there was no pre-existing session.

Additional context

The documentation suggests that the session is activated upon calling isAuthenticated(), but the session is already created in the constructor, and isAuthenticated() does nothing that can trigger a session to be created.

I didn't call \SimpleSAML\Session::getSessionFromRequest()->cleanup();, as there is no previous session it wouldn't have done anything.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions