Bug #67296 [Opn->Fbk]: filter_input doesn't validate variables set by nginx/php-fpm
Edit report at https://bugs.php.net/bug.php?id=67296&edit=1
ID: 67296
Updated by: tyrael@php.net
Reported by: fleshgrinder at gmx dot at
Summary: filter_input doesn't validate variables set by
nginx/php-fpm
-Status: Open
+Status: Feedback
Type: Bug
Package: Filter related
Operating System: Debian Wheezy
PHP Version: 5.6.0beta3
Block user comment: N
Private report: N
New Comment:
any chance that you are using auto_globals_jit?
somebody else also reported on the mailing list that input_filter won't trigger the jit
variable, so I wonder if this is the same or a different bug.
Previous Comments:
------------------------------------------------------------------------
[2014-05-16 22:34:47] fleshgrinder at gmx dot at
Description:
------------
I'm running nginx which communicates via FastCGI to php-fpm. The filter_input() function
doesn't validate any of the variables which are sent via FastCGI within the global $_SERVER
array.
Test script:
---------------
<?php
foreach ($_SERVER as $variable_name => $value) {
var_dump($value);
var_dump(filter_input(INPUT_SERVER, $variable_name, FILTER_UNSAFE_RAW));
}
?>
Expected result:
----------------
The filter_input() function should validate the variable within the $_SERVER array. I know that
filter_input() can't be used if you set something in your code but in my opinion it should
accept the data that was sent via FastCGI. Otherwise the function is pretty useless for non Apache
users.
Actual result:
--------------
Always returns NULL.
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=67296&edit=1
Thread (4 messages)