Bug #69523 [Com]: setcookie() uses second parameter as name (first param)

From: Date: Tue, 28 Apr 2015 23:50:06 +0000
Subject: Bug #69523 [Com]: setcookie() uses second parameter as name (first param)
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-192386@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=69523&edit=1 ID: 69523 Comment by: a at b dot c dot de Reported by: florian dot schmidt dot welzow at t-online dot de Summary: setcookie() uses second parameter as name (first param) Status: Not a bug Type: Bug Package: *Web Server problem Operating System: Ubuntu 14.04.2 PHP Version: Irrelevant Assigned To: cmb Block user comment: N Private report: N New Comment: That RFC gives the productions set-cookie-header = "Set-Cookie:" SP set-cookie-string set-cookie-string = cookie-pair *( ";" SP cookie-av ) cookie-pair = cookie-name "=" cookie-value cookie-name = token token = <token, defined in [RFC2616], Section 2.2> Where the latter reference defines "token" as token = 1*<any CHAR except CTLs or separators> CTL being ASCII control characters and "separators" being a list of punctuation marks. So a cookie-name has to be a token, which is by definition _at least_ one character long. Previous Comments: ------------------------------------------------------------------------ [2015-04-24 14:49:45] cmb@php.net Consider the following statement: setcookie('', 'value'); This constructs the following header field: Set-Cookie: =value This header field conforms to RFC 6265, section 4.1.1[1], because cookie-name may be empty. So PHP allows what is permitted according to the relevant RFC. What's happening on the client side is not a PHP issue. The behavior your are describing (name and value are swapped) happens on Chrome 42.0.2311.90 m, but not on Firefox 37.0.2, for instance. [1] <http://tools.ietf.org/html/rfc6265#section-4.1.1> ------------------------------------------------------------------------ [2015-04-24 10:55:49] florian dot schmidt dot welzow at t-online dot de Description: ------------ If you use the script provided in "Test script" section, you''ll set a new cookie with the name "value" and an empty value. That seems to be a false behavior, the name of the cookie is required[1] and php should throw a fatal error, if an empty name is provided. [1] http://php.net/manual/de/function.setcookie.php Test script: --------------- setcookie('', 'value', time()+10); var_dump($_COOKIE); Expected result: ---------------- Warning/Fatal error Actual result: -------------- A new cookie set with "value" as "name" ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=69523&edit=1

« previous php.bugs (#192386) next »