Bug #17050 Updated: PHP not reading/writing cookies properly
| From: | rasmus@php.net | Date: | Fri, 28 Jun 2002 05:45:05 +0000 |
| Subject: | Bug #17050 Updated: PHP not reading/writing cookies properly | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-12310@lists.php.net to get a copy of this message | ||
ID: 17050
Updated by: rasmus@php.net
Reported By: csaba@alum.mit.edu
-Status: Open
+Status: Bogus
Bug Type: *General Issues
PHP Version: 4.2.0
New Comment:
Cookies are treated like single GET or POST values in that their
contents are urldecoded. %20 is a space in standard urlencoding. As
you said, if you want to do your own decoding, you can simply use the
raw cookie string. You may not agree with the choice to urldecode, but
that doesn't mean it is a bug.
Previous Comments:
------------------------------------------------------------------------
[2002-06-28 01:35:39] csaba@alum.mit.edu
That's nice. I agree with your statement, but it has no bearing on my
bug report. That's why I've marked the status Open again.
I'll spell out what you are looking for. You have to run the test
twice because on the first invocation (from client to server) no
cookies have been set yet, as you point out. The second invocation on
IE can be accomplished by an F5 button, while with netscape, you may
have to clear the disk/memory cache since the client may not run out to
the server otherwise.
Upon this (second) test, you will notice that in the section
printed out by the php headers, we have an entry (correctly) reading:
Header Cookie: CookieTest=Var1=Hi%20Mom&Var2=Frob
Right below this we have another entry (correctly) reading:
Cookies according to browser:
CookieTest=Var1=Hi%20Mom&Var2=Frob
So now we know that the cookie we set was correctly received by the
browser, and that the server, in turn, has correctly received the
cookie that was on the client machine. Now let's see what PHP does
with it. In the PHP Variables (next to last) section of the phpinfo()
we have two entries reading:
_COOKIE["CookieTest"] | Var1=Hi Mom&Var2=Frob
_SERVER["HTTP_COOKIE"] | CookieTest=Var1=Hi%20Mom&Var2=Frob
Evidently, PHP has interpreted that %20 as a space. I have not been
able to find any documentation for this behaviour, and that is what I
am reporting. Browser documentation generally encourages using
escape() to ensure that no illegal characters are embedded within a
cookie, but this is not the only way. Ultimitely, it means that I
can't get all cookie values or use alternate encoding schemes unless I
go to the original _SERVER["HTTP_COOKIE"].
------------------------------------------------------------------------
[2002-06-27 23:09:50] sniper@php.net
Cookies are available to scripts in the NEXT run, not the same.
------------------------------------------------------------------------
[2002-05-28 09:39:23] stefan@traskelin.com
I was using PHP 4.1.1 on Win32 and Apache 1.3.24. I had to restart my
server and then it doesn't seem to work any longer.
I have reinstalled Apache and updated PHP to 4.2.1. The PHP script
doesn't seem to get the value. However when I include the
phpinfo()-function, it can tell me about the cookies...
------------------------------------------------------------------------
[2002-05-21 02:36:03] jbeck@terabit.ca
One of my servers froze. When I rebooted it would no longer read any
cookies. I don't know if the freezing is related but it might be...
I am using php 4.0.6
------------------------------------------------------------------------
[2002-05-10 09:40:25] arat155@icqmail.com
I have the same problem.
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
http://bugs.php.net/17050
--
Edit this bug report at http://bugs.php.net/?id=17050&edit=1