Bug #68954 [NEW]: DateTime::COOKIE does not match setcookie() or any RFC
| From: | AgentConundrum at gmail dot com | Date: | Fri, 30 Jan 2015 02:06:37 +0000 |
| Subject: | Bug #68954 [NEW]: DateTime::COOKIE does not match setcookie() or any RFC | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-190329@lists.php.net to get a copy of this message | ||
From: AgentConundrum at gmail dot com
Operating system: *
PHP version: 5.6Git-2015-01-30 (snap)
Package: *General Issues
Bug Type: Bug
Bug description:DateTime::COOKIE does not match setcookie() or any RFC
Description:
------------
There is a contradiction between the format sent by setcookie() and the
format defined by \DateTime::COOKIE. \DateTime::COOKIE also does not
appear to match any cookie RFC.
setcookie Format: "D, d-M-Y H:i:s T" (see [1],[2])
DateTime::COOKIE: "l, d-M-Y H:i:s T" (see [3])
The setcookie() format appears to be the correct/commonly-used value.
RFC6265 defines the sane-cookie-date format to be in rfc-1123, which
uses the abbreviated wkday. DateTime::COOKIE, however uses the full
weekday.
This is confusing as one would assume that the COOKIE constant would
reflect the format actually used on a cookie.
There is a note in php_date.c above the DateTime::COOKIE definition
explaining why that format was selected. However, both references in
that comment point to the abbreviated weekday. I believe the comment is
instead trying to explain the hyphenated date format only, as the rfc
uses spaces. The hyphenated version is more common.
[1] https://github.com/php/php-src/blob/master/ext/standard/head.c#L123
[2] https://github.com/php/php-src/blob/master/ext/standard/head.c#L132
[3] https://github.com/php/php-src/blob/master/ext/date/php_date.c#L818
Test script:
---------------
ob_start();
$cookie_time = time() + 3600;
setcookie('Key', 'Value', $cookie_time);
$dt = new \DateTime(date('c', $cookie_time));
$dt->setTimeZone(new \DateTimeZone('GMT'));
$fmt = $dt->format(\DateTime::COOKIE);
$cookie_found = false;
foreach(headers_list() as $header) {
if (strpos($header, $fmt) !== false) {
$cookie_found = true;
break;
}
}
assert($cookie_found);
Expected result:
----------------
Assertion passes. The expires portion of the cookie header matches
\DateTime::COOKIE.
Actual result:
--------------
Assertion fails because \DateTime::COOKIE uses the full weekday rather
than the abbreviation.
--
Edit bug report at https://bugs.php.net/bug.php?id=68954&edit=1
--
Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=68954&r=trysnapshot54
Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=68954&r=trysnapshot55
Try a snapshot (trunk): https://bugs.php.net/fix.php?id=68954&r=trysnapshottrunk
Fixed in SVN: https://bugs.php.net/fix.php?id=68954&r=fixed
Fixed in release: https://bugs.php.net/fix.php?id=68954&r=alreadyfixed
Need backtrace: https://bugs.php.net/fix.php?id=68954&r=needtrace
Need Reproduce Script: https://bugs.php.net/fix.php?id=68954&r=needscript
Try newer version: https://bugs.php.net/fix.php?id=68954&r=oldversion
Not developer issue: https://bugs.php.net/fix.php?id=68954&r=support
Expected behavior: https://bugs.php.net/fix.php?id=68954&r=notwrong
Not enough info: https://bugs.php.net/fix.php?id=68954&r=notenoughinfo
Submitted twice: https://bugs.php.net/fix.php?id=68954&r=submittedtwice
register_globals: https://bugs.php.net/fix.php?id=68954&r=globals
PHP 4 support discontinued: https://bugs.php.net/fix.php?id=68954&r=php4
Daylight Savings: https://bugs.php.net/fix.php?id=68954&r=dst
IIS Stability: https://bugs.php.net/fix.php?id=68954&r=isapi
Install GNU Sed: https://bugs.php.net/fix.php?id=68954&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=68954&r=float
No Zend Extensions: https://bugs.php.net/fix.php?id=68954&r=nozend
MySQL Configuration Error: https://bugs.php.net/fix.php?id=68954&r=mysqlcfg