• Resolved Horacio Figarella

    (@hfigarella)


    Hi,

    We run Inactive Logout on about a dozen sites (PHP 8.4 and 8.5) with concurrent-login limiting on. **3.6.3** (current trunk) can throw a hard fatal in
    core/ConcurrentLogin.php, concurrent_logins():

    <br><br>PHP Fatal error: Uncaught ValueError: max(): Argument #1 ($value) must contain at least one element in .../inactive-logout/core/ConcurrentLogin.php:80<br><br>

    **Lines 79-82:**

    php<br><br>$sessions = wp_get_all_sessions();<br><br>$newest   = max( wp_list_pluck( $sessions, 'login' ) );<br><br>$session  = $this->get_current_session();<br><br>if ( $session&#091;'login'] === $newest ) {<br><br>

    Two things can go wrong here:

    1. **Line 80:** wp_get_all_sessions() can return an empty array if the tokens expire or are destroyed (for example by wp_destroy_all_sessions() from another plugin) between the user_has_multiple_sessions() check on line 53 and this call. On PHP 7, max() on an empty array was only a warning. On PHP 8+ it throws a ValueError, which white-screens the request.

    2. **Line 82:** get_current_session() returns WP_Session_Tokens::get(), which is null when the current token no longer exists. $session&#091;'login'] then logs "Trying to access array offset on value of type null".

    **Suggested fix:** two guards, no change in behaviour when sessions exist:

    php<br><br>$sessions = wp_get_all_sessions();<br><br>if ( empty( $sessions ) ) return;<br><br>$newest   = max( wp_list_pluck( $sessions, 'login' ) );<br><br>$session  = $this->get_current_session();<br><br>if ( ! is_array( $session ) ) return;<br><br>if ( $session&#091;'login'] === $newest ) {<br><br>

    **To reproduce:** a logged-in user with 2+ sessions whose session store empties, or whose current token is destroyed, between the multiple-sessions check and these lines.

    **Expected:** the function returns quietly, with no fatal and no warning.

    **Environment:** WordPress 7.2-alpha (nightly), PHP 8.4.25 and 8.5.11, Inactive Logout 3.6.3.

    We carry these two guards as a local patch and re-apply them after each update. It would be great to have them upstream. Thanks!
Viewing 1 replies (of 1 total)
Viewing 1 replies (of 1 total)

You must be logged in to reply to this topic.