Bug #67736 [Com]: setcookie() not updating existing cookies

From: Date: Mon, 01 Sep 2014 00:19:20 +0000
Subject: Bug #67736 [Com]: setcookie() not updating existing cookies
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-187359@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=67736&edit=1 ID: 67736 Comment by: Danack at basereality dot com Reported by: brad at bradb dot net Summary: setcookie() not updating existing cookies Status: Verified Type: Bug Package: *General Issues Operating System: Linux (Ubuntu) PHP Version: 5.6.0 Block user comment: N Private report: N New Comment: (X-posting from PR) The PHP code does not have a bug. The RFC does not forbid sending multiple cookies with the same name: "Servers SHOULD NOT include more than one Set-Cookie header field in the same response with the same cookie-name. (See Section 5.2 for how user agents handle this case.)" Although it is definitely not recommended, the RFC does not say MUST NOT. Even if it was forbidden by the RFC, it is not PHP's job to enforce conformance to RFCs. That is up to the programmer using PHP to not send improper data. The idea of having setcookie magically modifying the cookie header that is sent is not good. It would be adding more magic behaviour to PHP to cover up the fact that the programmer who is calling setcookie() has a bug in their code. Adding a warning is enough. It tells people that they are doing something that is probably unwise, but is technically allowed. Doing anything more is not only the wrong thing to do anyway, but introduces a backwards compatibility break for no good reason. If someone is unaware they are calling setcookie() twice with the same name, the error will alert them and allow them to fix their code. If someone is deliberately calling setcookie() twice with the same name (e.g. for a legacy application that knows how to handle multiple cookies with the same name) then they will need to continue using the current behaviour. Changing the behaviour just because it would be a bit 'better' is not a good idea. There needs to be a clear reason for changing the behaviour, and I don't think there is one here. Previous Comments: ------------------------------------------------------------------------ [2014-08-01 17:10:15] tyrael@php.net I think we should fix this. rfc6265 (latest rfc defining http cookies) states that "Servers SHOULD NOT include more than one Set-Cookie header field in the same response with the same cookie-name." ------------------------------------------------------------------------ [2014-08-01 14:02:28] brad at bradb dot net Description: ------------ Multiple calls to setcookie() with the same name are not resulting in the cookie header being updated, but instead appended. So the headers are being returned with multiple cookies of the same name. As there seems to be no standard for which browsers select in this instance, it creates headaches! Also reinstalled 5.5.9 and seeing the same issue, again via the Ubuntu package. It seems to occur with both setcookie() and setrawcookie(). A simple test will show the issue: Here's the output of the test script. Test script: --------------- <?php setcookie("test", "abc"); setcookie("test", "def"); Expected result: ---------------- HTTP/1.1 200 OK Date: Fri, 01 Aug 2014 13:46:05 GMT Server: Apache/2.4.10 (Ubuntu) X-Powered-By: PHP/5.6.0RC2 Set-Cookie: test=def Access-Control-Allow-Origin: * Access-Control-Allow-Methods: POST, GET, OPTIONS, DELETE, PUT, HEAD Access-Control-Allow-Headers: Origin,Content-Type,Accept,Authorization Content-Length: 0 Keep-Alive: timeout=5, max=100 Connection: Keep-Alive Content-Type: text/html; charset=UTF-8 Actual result: -------------- HTTP/1.1 200 OK Date: Fri, 01 Aug 2014 13:46:05 GMT Server: Apache/2.4.10 (Ubuntu) X-Powered-By: PHP/5.6.0RC2 Set-Cookie: test=abc Set-Cookie: test=def Access-Control-Allow-Origin: * Access-Control-Allow-Methods: POST, GET, OPTIONS, DELETE, PUT, HEAD Access-Control-Allow-Headers: Origin,Content-Type,Accept,Authorization Content-Length: 0 Keep-Alive: timeout=5, max=100 Connection: Keep-Alive Content-Type: text/html; charset=UTF-8 ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=67736&edit=1

« previous php.bugs (#187359) next »