Bug #67736 [Com]: setcookie() not updating existing cookies
| From: | Danack at basereality dot com | Date: | Mon, 01 Sep 2014 00:19:20 +0000 |
| Subject: | Bug #67736 [Com]: setcookie() not updating existing cookies | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-187359@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=67736&edit=1
ID: 67736
Comment by: Danack at basereality dot com
Reported by: brad at bradb dot net
Summary: setcookie() not updating existing cookies
Status: Verified
Type: Bug
Package: *General Issues
Operating System: Linux (Ubuntu)
PHP Version: 5.6.0
Block user comment: N
Private report: N
New Comment:
(X-posting from PR)
The PHP code does not have a bug. The RFC does not forbid sending multiple cookies with the same
name:
"Servers SHOULD NOT include more than one Set-Cookie header field in the same response with the
same cookie-name. (See Section 5.2 for how user agents handle this case.)"
Although it is definitely not recommended, the RFC does not say MUST NOT.
Even if it was forbidden by the RFC, it is not PHP's job to enforce conformance to RFCs. That
is up to the programmer using PHP to not send improper data.
The idea of having setcookie magically modifying the cookie header that is sent is not good. It
would be adding more magic behaviour to PHP to cover up the fact that the programmer who is calling
setcookie() has a bug in their code.
Adding a warning is enough. It tells people that they are doing something that is probably unwise,
but is technically allowed. Doing anything more is not only the wrong thing to do anyway, but
introduces a backwards compatibility break for no good reason.
If someone is unaware they are calling setcookie() twice with the same name, the error will alert
them and allow them to fix their code.
If someone is deliberately calling setcookie() twice with the same name (e.g. for a legacy
application that knows how to handle multiple cookies with the same name) then they will need to
continue using the current behaviour.
Changing the behaviour just because it would be a bit 'better' is not a good idea. There
needs to be a clear reason for changing the behaviour, and I don't think there is one here.
Previous Comments:
------------------------------------------------------------------------
[2014-08-01 17:10:15] tyrael@php.net
I think we should fix this.
rfc6265 (latest rfc defining http cookies) states that
"Servers SHOULD NOT include more than one Set-Cookie header field in the same response with the
same cookie-name."
------------------------------------------------------------------------
[2014-08-01 14:02:28] brad at bradb dot net
Description:
------------
Multiple calls to setcookie() with the same name are not resulting in the cookie header being
updated, but instead appended. So the headers are being returned with multiple cookies of the same
name. As there seems to be no standard for which browsers select in this instance, it creates
headaches!
Also reinstalled 5.5.9 and seeing the same issue, again via the Ubuntu package.
It seems to occur with both setcookie() and setrawcookie(). A simple test will show the issue:
Here's the output of the test script.
Test script:
---------------
<?php
setcookie("test", "abc");
setcookie("test", "def");
Expected result:
----------------
HTTP/1.1 200 OK
Date: Fri, 01 Aug 2014 13:46:05 GMT
Server: Apache/2.4.10 (Ubuntu)
X-Powered-By: PHP/5.6.0RC2
Set-Cookie: test=def
Access-Control-Allow-Origin: *
Access-Control-Allow-Methods: POST, GET, OPTIONS, DELETE, PUT, HEAD
Access-Control-Allow-Headers: Origin,Content-Type,Accept,Authorization
Content-Length: 0
Keep-Alive: timeout=5, max=100
Connection: Keep-Alive
Content-Type: text/html; charset=UTF-8
Actual result:
--------------
HTTP/1.1 200 OK
Date: Fri, 01 Aug 2014 13:46:05 GMT
Server: Apache/2.4.10 (Ubuntu)
X-Powered-By: PHP/5.6.0RC2
Set-Cookie: test=abc
Set-Cookie: test=def
Access-Control-Allow-Origin: *
Access-Control-Allow-Methods: POST, GET, OPTIONS, DELETE, PUT, HEAD
Access-Control-Allow-Headers: Origin,Content-Type,Accept,Authorization
Content-Length: 0
Keep-Alive: timeout=5, max=100
Connection: Keep-Alive
Content-Type: text/html; charset=UTF-8
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=67736&edit=1