Bug #67955 [NEW]: SoapClient prepends 0-byte to cookie names
| From: | phofstetter at sensational dot ch | Date: | Wed, 03 Sep 2014 12:30:35 +0000 |
| Subject: | Bug #67955 [NEW]: SoapClient prepends 0-byte to cookie names | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-187401@lists.php.net to get a copy of this message | ||
From: phofstetter at sensational dot ch
Operating system: OSX and Linux
PHP version: master-Git-2014-09-03 (Git)
Package: SOAP related
Bug Type: Bug
Bug description:SoapClient prepends 0-byte to cookie names
Description:
------------
When sending a Cookie back to the server, SoapClient appends a 0-byte to
the name of the cookie.
I have tracked this down to commit
6c2a8068207a02b3d7ae7416a9967dad0a81e61f that changed
smart_str_appendl(&soap_headers, key, strlen(key));
to
smart_str_appendl(&soap_headers, key, key_len);
in soap/php_http.c
I'm not too versed in the internals of PHP, but it looks to me like
zend_hash_get_current_key_ex which is now used instead of
zend_hash_get_current_key is returning the length of the value which
includes the 0-terminator in case of strings and smart_str_appendl
assumes the length to be without the 0 terminator (which is obvious when
you look at the code pre-patch).
The fix is to either change that line to
smart_str_appendl(&soap_headers, key, key_len-1);
or
smart_str_appendl(&soap_headers, key, strlen(key));
Or to fix smart_srt_appendl, but that's used all over the code and
assumes the length to be the string length, not the byte length, so that
feels too invasive to me.
I will provide a patch to do the former, but feel free to do the
latter.
Expected result:
----------------
when the server sends
Set-Cookie: JSESSIONID=foobar
I expect SoapClient to send
Cookie: JSESSIONID=foobar
Actual result:
--------------
SoapClient sends
Cookie: JSESSIONID_NULL_=foobar
--
Edit bug report at https://bugs.php.net/bug.php?id=67955&edit=1
--