Bug #68954 [Opn]: DateTime::COOKIE does not match setcookie() or any RFC

From: Date: Fri, 30 Jan 2015 03:21:11 +0000
Subject: Bug #68954 [Opn]: DateTime::COOKIE does not match setcookie() or any RFC
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-190334@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=68954&edit=1

 ID:                 68954
 User updated by:    AgentConundrum at gmail dot com
 Reported by:        AgentConundrum at gmail dot com
 Summary:            DateTime::COOKIE does not match setcookie() or any
                     RFC
 Status:             Open
 Type:               Bug
 Package:            *General Issues
 Operating System:   *
-PHP Version:        5.6Git-2015-01-30 (snap)
+PHP Version:        master-Git-2015-01-30 (Git)
 Block user comment: N
 Private report:     N

 New Comment:

Used wrong version option.


Previous Comments:
------------------------------------------------------------------------
[2015-01-30 02:06:36] AgentConundrum at gmail dot com

Description:
------------
There is a contradiction between the format sent by setcookie() and the format defined by
\DateTime::COOKIE. \DateTime::COOKIE also does not appear to match any cookie RFC.

setcookie Format: "D, d-M-Y H:i:s T" (see [1],[2])
DateTime::COOKIE: "l, d-M-Y H:i:s T" (see [3])

The setcookie() format appears to be the correct/commonly-used value. RFC6265 defines the
sane-cookie-date format to be in rfc-1123, which uses the abbreviated wkday. DateTime::COOKIE,
however uses the full weekday.

This is confusing as one would assume that the COOKIE constant would reflect the format actually
used on a cookie.

There is a note in php_date.c above the DateTime::COOKIE definition explaining why that format was
selected. However, both references in that comment point to the abbreviated weekday. I believe the
comment is instead trying to explain the hyphenated date format only, as the rfc uses spaces. The
hyphenated version is more common.

[1] https://github.com/php/php-src/blob/master/ext/standard/head.c#L123
[2] https://github.com/php/php-src/blob/master/ext/standard/head.c#L132
[3] https://github.com/php/php-src/blob/master/ext/date/php_date.c#L818

Test script:
---------------
ob_start();
$cookie_time = time() + 3600;
setcookie('Key', 'Value', $cookie_time);

$dt = new \DateTime(date('c', $cookie_time));
$dt->setTimeZone(new \DateTimeZone('GMT'));
$fmt = $dt->format(\DateTime::COOKIE);

$cookie_found = false;
foreach(headers_list() as $header) {
  if (strpos($header, $fmt) !== false) {
    $cookie_found = true;
    break;
  }
}
assert($cookie_found);

Expected result:
----------------
Assertion passes. The expires portion of the cookie header matches \DateTime::COOKIE.

Actual result:
--------------
Assertion fails because \DateTime::COOKIE uses the full weekday rather than the abbreviation.


------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=68954&edit=1


Thread (7 messages)

« previous php.bugs (#190334) next »