From b59c80123dcf09fb9871fecd34ad5f96c35b1fd7 Mon Sep 17 00:00:00 2001 From: "Simon L." Date: Tue, 25 Aug 2026 14:19:04 +0200 Subject: [PATCH] Remove migration code for the aio-interface session cookie rename The session cookie was renamed from PHPSESSID to __Host-Http-PHPSESSID in v13.0.0 and PRs #7964 and #7971 added transitional code that carried an existing PHPSESSID login over to the new cookie. Everyone has long since been migrated, so this reverts both PRs. Closes #7966 Co-Authored-By: Claude Opus 5 (1M context) Signed-off-by: Simon L. --- php/public/index.php | 29 ----------------------------- php/src/Auth/AuthManager.php | 14 +------------- 2 files changed, 1 insertion(+), 42 deletions(-) diff --git a/php/public/index.php b/php/public/index.php index 1b0a675f..fe9052b7 100644 --- a/php/public/index.php +++ b/php/public/index.php @@ -40,24 +40,6 @@ $container->set(Guard::class, function () use ($responseFactory) { }); // Register Middleware To Be Executed On All Routes - -// Migrate from the old PHPSESSID cookie to the new __Host-Http-PHPSESSID cookie. -// This is needed because the session cookie was renamed in a previous release. Without this, -// users that were logged in before the update would be logged out after the container restarts. -$wasAuthenticated = false; -$oldSessionTimestamp = null; -if (!isset($_COOKIE['__Host-Http-PHPSESSID']) && isset($_COOKIE['PHPSESSID'])) { - session_name('PHPSESSID'); - if (session_start(['save_path' => $dataConst->GetSessionDirectory(), 'use_strict_mode' => true])) { - $wasAuthenticated = isset($_SESSION[\AIO\Auth\AuthManager::SESSION_KEY]) && $_SESSION[\AIO\Auth\AuthManager::SESSION_KEY] === true; - $oldSessionTimestamp = isset($_SESSION['date_time']) ? (int)$_SESSION['date_time'] : null; - // Do not destroy the old session: if the response carrying the new __Host-Http-PHPSESSID - // cookie is lost (e.g., due to a 502 during a mastercontainer update), the client can - // retry with the old PHPSESSID cookie and still be authenticated. - session_write_close(); - } -} - session_start([ "name" => "__Host-Http-PHPSESSID", // Set cookie prefix to prevent other pages from overwriting this cookie. See https://developer.mozilla.org/en-US/docs/Web/HTTP/Reference/Headers/Set-Cookie#cookie_prefixes "save_path" => $dataConst->GetSessionDirectory(), // Where to save the session files @@ -71,17 +53,6 @@ session_start([ "cookie_samesite" => "Lax", // Send the cookie with same-site requests and top-level cross-site navigations (e.g. redirect after token-based getlogin). "Strict" would block the session cookie on the redirect that follows a cross-site navigation, breaking the getlogin flow from Nextcloud's admin panel. See https://developer.mozilla.org/en-US/docs/Web/HTTP/Reference/Headers/Set-Cookie#samesitesamesite-value ]); -if ($wasAuthenticated) { - if ($oldSessionTimestamp !== null) { - // Use MigrateAuthState to preserve the original login timestamp. This prevents the - // session deduplicator from running and keeps the old PHPSESSID session file alive, - // so the client can retry with the old cookie if the 502 response causes the new - // __Host-Http-PHPSESSID cookie to not be received. - $container->get(\AIO\Auth\AuthManager::class)->MigrateAuthState($oldSessionTimestamp); - } else { - $container->get(\AIO\Auth\AuthManager::class)->SetAuthState(true); - } -} $app->add(Guard::class); // Create Twig diff --git a/php/src/Auth/AuthManager.php b/php/src/Auth/AuthManager.php index 9d2718e0..e2ff98dc 100644 --- a/php/src/Auth/AuthManager.php +++ b/php/src/Auth/AuthManager.php @@ -8,7 +8,7 @@ use AIO\Data\DataConst; use \DateTime; readonly class AuthManager { - public const string SESSION_KEY = 'aio_authenticated'; + private const string SESSION_KEY = 'aio_authenticated'; public function __construct( private ConfigurationManager $configurationManager @@ -42,18 +42,6 @@ readonly class AuthManager { $_SESSION[self::SESSION_KEY] = $isLoggedIn; } - /** - * Migrates the authenticated state from an old session (different cookie name) to the new session. - * Unlike SetAuthState, this method preserves the original login timestamp and does not update - * the session_date_file, so the session deduplicator is not triggered. This keeps the old session - * file alive in case the response carrying the new cookie is lost (e.g., due to a 502 error during - * a mastercontainer update), allowing the client to retry with the old cookie. - */ - public function MigrateAuthState(int $oldTimestamp) : void { - $_SESSION[self::SESSION_KEY] = true; - $_SESSION['date_time'] = $oldTimestamp; - } - public function IsAuthenticated() : bool { return isset($_SESSION[self::SESSION_KEY]) && $_SESSION[self::SESSION_KEY] === true; }