#48190 [Opn->Asn]: Content-type parameter "boundary" is not case-insensitive in HTTP uploads

From: Date: Mon, 30 Nov 2009 20:03:46 +0000
Subject: #48190 [Opn->Asn]: Content-type parameter "boundary" is not case-insensitive in HTTP uploads
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-145241@lists.php.net to get a copy of this message
ID: 48190 Updated by: jani@php.net Reported By: carsten_sttgt at gmx dot de -Status: Open +Status: Assigned Bug Type: HTTP related Operating System: Windows NT PHP Version: 5.*CVS, 6CVS (2009-05-08) Assigned To: garretts New Comment: So, where's the fix? Previous Comments: ------------------------------------------------------------------------ [2009-10-07 22:28:19] garretts@php.net I'm testing a fix I've built for this right now. ------------------------------------------------------------------------ [2009-05-09 04:08:27] jani@php.net Yes, I know it's not an upload per se, but the code that handles is one that most of the time takes care of file uploads. :) Problem is in rfc1867.c:804, strstr() should be replaced with something that does the same but case-insensitively. ------------------------------------------------------------------------ [2009-05-08 23:23:57] carsten_sttgt at gmx dot de > Just curious, but what client actually uses > uppercase/mixed case "boundary" parameter name? I'm using imap_mail_compose() to build the 'header' and 'content' keys in the stream_context_create() options array. And then using this context with e.g. file_get_contents() to make the POST request. BTW: The above example is a HTTP POST request without a file upload. ------------------------------------------------------------------------ [2009-05-08 22:05:58] jani@php.net Just curious, but what client actually uses uppercase/mixed case "boundary" parameter name? (and ------------------------------------------------------------------------ [2009-05-08 21:41:55] carsten_sttgt at gmx dot de In my first post I have refereed to RFC2045, but RFC2616 is also very clear about this [1]: | The type, subtype, and parameter attribute names are | case- insensitive. Parameter values might or might | not be case-sensitive, depending on the semantics | of the parameter name. type = MULTIPART subtype = form-data parameter attribute name = BOUNDARY parameter value = 250-16659-1241787336=:9320 [1] http://www.w3.org/Protocols/rfc2616/rfc2616-sec3.html#sec3.7 ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at http://bugs.php.net/48190 -- Edit this bug report at http://bugs.php.net/?id=48190&edit=1

« previous php.bugs (#145241) next »