Bug #50921 [ReO]: '200 OK' HTTP status despite PHP error

From: Date: Wed, 09 Jul 2014 23:00:29 +0000
Subject: Bug #50921 [ReO]: '200 OK' HTTP status despite PHP error
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-186550@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=50921&edit=1

 ID:                 50921
 Updated by:         yohgaki@php.net
 Reported by:        phpbug at starurl dot com
 Summary:            '200 OK' HTTP status despite PHP error
 Status:             Re-Opened
 Type:               Bug
 Package:            HTTP related
 Operating System:   *
 PHP Version:        5.2.12
 Block user comment: N
 Private report:     N

 New Comment:

See also
https://bugs.php.net/bug.php?id=61417


Previous Comments:
------------------------------------------------------------------------
[2014-07-08 20:38:33] jonathan at spoonity dot com

Ah yes, I remember that. The IE limit a minimum of 512 byte of data to show  the outputted data.
Perhaps there could be an ini setting to choose if the status code will be 200 or 500, with the
default being the current behaviour?

------------------------------------------------------------------------
[2014-07-08 19:28:31] tyrael@php.net

here is the thread I've started about this behavior:
http://www.serverphorums.com/read.php?7,965893
it turned out that we added the explicit display_errors check for not setting the http 500 response
code because Internet Explore will show a custom error page for non-2xx responses if the length of
the response body is less than an arbitrary threshold, hence it won't show the error message if
we set the http 500.
I don't think that this change was a good idea back then, but it is possible that changing it
now would cause more harm than good.
I will keep this ticket open until we either reach a consensus that this should be fixed in a future
release, or should be kept as-is and the documentation is updated to reflect current behavior.

------------------------------------------------------------------------
[2014-07-08 17:19:55] jonathan at spoonity dot com

A workaround for those interested is the following:

register_shutdown_function(function() {
    $error = error_get_last();
    if ($error['type'] == E_ERROR) {
        header('HTTP/1.1 500 Internal Server Error');
    }
});

Be nice to see this fixed without this workaround though.

------------------------------------------------------------------------
[2014-06-25 08:57:49] tyrael@php.net

oh, it seems we are explicitly checking for display_errors when setting the 500 response code:
http://lxr.php.net/xref/PHP_5_4/main/main.c#1154
I will ask the others on the internals list for the reason for this.

------------------------------------------------------------------------
[2014-06-25 08:10:00] tyrael@php.net

the xdebug issue was a separate problem, and is indeed fixed.
what is still not "fixed" is that if you enable display_errors, then the error message
itself will trigger sending out the response which sets the http 200 implicitly.
if we go ahead and change this, we should make sure to only add the http 500 when the script
execution is actually terminated by the error(for example E_RECOVERABLE_ERROR will or won't
stop the execution based on the return value of the user defined error handler) as we don't
wanna start sending http 500 responses for every notice and stuff.

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=50921


--
Edit this bug report at https://bugs.php.net/bug.php?id=50921&edit=1


Thread (33 messages)

« previous php.bugs (#186550) next »