Bug #67955 [Opn->Csd]: SoapClient prepends 0-byte to cookie names
| From: | datibbaw@php.net | Date: | Wed, 03 Sep 2014 23:01:19 +0000 |
| Subject: | Bug #67955 [Opn->Csd]: SoapClient prepends 0-byte to cookie names | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-187407@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=67955&edit=1
ID: 67955
Updated by: datibbaw@php.net
Reported by: phofstetter at sensational dot ch
Summary: SoapClient prepends 0-byte to cookie names
-Status: Open
+Status: Closed
Type: Bug
Package: SOAP related
Operating System: OSX and Linux
PHP Version: master-Git-2014-09-03 (Git)
Block user comment: N
Private report: N
New Comment:
Automatic comment on behalf of datibbaw
Revision: http://git.php.net/?p=php-src.git;a=commit;h=fa08ff924513d10ecd450e590865dc2926371f3a
Log: Fixed #67955: SoapClient prepends 0-byte to cookie names
Previous Comments:
------------------------------------------------------------------------
[2014-09-03 12:32:06] phofstetter at sensational dot ch
Commit reference on github would be
https://github.com/php/php-src/commit/6c2a8068207a02b3d7ae7416a9967dad0a81e61f
------------------------------------------------------------------------
[2014-09-03 12:30:34] phofstetter at sensational dot ch
Description:
------------
When sending a Cookie back to the server, SoapClient appends a 0-byte to the name of the cookie.
I have tracked this down to commit 6c2a8068207a02b3d7ae7416a9967dad0a81e61f that changed
smart_str_appendl(&soap_headers, key, strlen(key));
to
smart_str_appendl(&soap_headers, key, key_len);
in soap/php_http.c
I'm not too versed in the internals of PHP, but it looks to me like
zend_hash_get_current_key_ex which is now used instead of zend_hash_get_current_key is returning the
length of the value which includes the 0-terminator in case of strings and smart_str_appendl assumes
the length to be without the 0 terminator (which is obvious when you look at the code pre-patch).
The fix is to either change that line to
smart_str_appendl(&soap_headers, key, key_len-1);
or
smart_str_appendl(&soap_headers, key, strlen(key));
Or to fix smart_srt_appendl, but that's used all over the code and assumes the length to be the
string length, not the byte length, so that feels too invasive to me.
I will provide a patch to do the former, but feel free to do the latter.
Expected result:
----------------
when the server sends
Set-Cookie: JSESSIONID=foobar
I expect SoapClient to send
Cookie: JSESSIONID=foobar
Actual result:
--------------
SoapClient sends
Cookie: JSESSIONID_NULL_=foobar
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=67955&edit=1