Bug #67736 [Opn->Ver]: setcookie() not updating existing cookies
| From: | tyrael@php.net | Date: | Fri, 01 Aug 2014 17:10:16 +0000 |
| Subject: | Bug #67736 [Opn->Ver]: setcookie() not updating existing cookies | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-186921@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=67736&edit=1
ID: 67736
Updated by: tyrael@php.net
Reported by: brad at bradb dot net
Summary: setcookie() not updating existing cookies
-Status: Open
+Status: Verified
Type: Bug
Package: *General Issues
Operating System: Linux (Ubuntu)
-PHP Version: 5.6.0RC3
+PHP Version: 5.6.0
Block user comment: N
Private report: N
New Comment:
I think we should fix this.
rfc6265 (latest rfc defining http cookies) states that
"Servers SHOULD NOT include more than one Set-Cookie header field in the same response with the
same cookie-name."
Previous Comments:
------------------------------------------------------------------------
[2014-08-01 14:02:28] brad at bradb dot net
Description:
------------
Multiple calls to setcookie() with the same name are not resulting in the cookie header being
updated, but instead appended. So the headers are being returned with multiple cookies of the same
name. As there seems to be no standard for which browsers select in this instance, it creates
headaches!
Also reinstalled 5.5.9 and seeing the same issue, again via the Ubuntu package.
It seems to occur with both setcookie() and setrawcookie(). A simple test will show the issue:
Here's the output of the test script.
Test script:
---------------
<?php
setcookie("test", "abc");
setcookie("test", "def");
Expected result:
----------------
HTTP/1.1 200 OK
Date: Fri, 01 Aug 2014 13:46:05 GMT
Server: Apache/2.4.10 (Ubuntu)
X-Powered-By: PHP/5.6.0RC2
Set-Cookie: test=def
Access-Control-Allow-Origin: *
Access-Control-Allow-Methods: POST, GET, OPTIONS, DELETE, PUT, HEAD
Access-Control-Allow-Headers: Origin,Content-Type,Accept,Authorization
Content-Length: 0
Keep-Alive: timeout=5, max=100
Connection: Keep-Alive
Content-Type: text/html; charset=UTF-8
Actual result:
--------------
HTTP/1.1 200 OK
Date: Fri, 01 Aug 2014 13:46:05 GMT
Server: Apache/2.4.10 (Ubuntu)
X-Powered-By: PHP/5.6.0RC2
Set-Cookie: test=abc
Set-Cookie: test=def
Access-Control-Allow-Origin: *
Access-Control-Allow-Methods: POST, GET, OPTIONS, DELETE, PUT, HEAD
Access-Control-Allow-Headers: Origin,Content-Type,Accept,Authorization
Content-Length: 0
Keep-Alive: timeout=5, max=100
Connection: Keep-Alive
Content-Type: text/html; charset=UTF-8
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=67736&edit=1