Skip to content

fix(di): bind Session\SessionLifecycle to its factory explicitly - #231

Open
jcdelepine wants to merge 1 commit into
horde:FRAMEWORK_6_0from
jcdelepine:fix/bind_Session_SessionLifecycle
Open

jcdelepine wants to merge 1 commit into
horde:FRAMEWORK_6_0from
jcdelepine:fix/bind_Session_SessionLifecycle

Conversation

@jcdelepine

@jcdelepine jcdelepine commented Sep 20, 2026

Copy link
Copy Markdown
Contributor

SessionLifecycleFactory (introduced by e1548bd) absorbs a legacy type mismatch: SessionLifecycle's constructor expects a SessionSecret, but the legacy 'Horde_Secret_Cbc' DI binding resolves to Horde_Core_Secret_Cbc, which does not implement that interface. The factory checks instanceof and falls back to a no-secret, rekey-disabled lifecycle instead of a fatal type error. Bare constructor reflection (the injector's fallback without an explicit binding) bypasses this factory entirely, reopening the exact failure e1548bd fixed — same failure class as #190 (Session\HordeSessionFactory).

Bind Session\SessionLifecycle::class => Session\SessionLifecycleFactory::class in DefaultInjectorBindings.php so the container always goes through the factory's compatibility handling.

Spotted while working on the OIDC integration — base's login/logout refactor already relies on SessionLifecycle via LoginServiceFactory, which is what surfaced the missing binding. Unrelated to OIDC itself and has no dependency on those PRs, same failure class as #190.

SessionLifecycleFactory (introduced by e1548bd) absorbs a legacy type
mismatch: SessionLifecycle's constructor expects a SessionSecret, but the
legacy 'Horde_Secret_Cbc' DI binding resolves to Horde_Core_Secret_Cbc,
which does not implement that interface. The factory checks instanceof
and falls back to a no-secret, rekey-disabled lifecycle instead of a
fatal type error. Bare constructor reflection (the injector's fallback
without an explicit binding) bypasses this factory entirely, reopening
the exact failure e1548bd fixed — same failure class as horde#190
(Session\HordeSessionFactory).

Bind Session\SessionLifecycle::class => Session\SessionLifecycleFactory::class
in DefaultInjectorBindings.php so the container always goes through the
factory's compatibility handling.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant