Bug #69523 [Nab]: setcookie() uses second parameter as name (first param)
Edit report at https://bugs.php.net/bug.php?id=69523&edit=1
ID: 69523
Updated by: requinix@php.net
Reported by: florian dot schmidt dot welzow at t-online dot de
Summary: setcookie() uses second parameter as name (first
param)
Status: Not a bug
Type: Bug
Package: *Web Server problem
Operating System: Ubuntu 14.04.2
PHP Version: Irrelevant
Assigned To: cmb
Block user comment: N
Private report: N
New Comment:
Given that a name-less Set-Cookie header can cause problems (at the very least unexpected, probably
browser-dependent behavior), a warning and no header seems like a good idea. Would be an easy patch
too.
Previous Comments:
------------------------------------------------------------------------
[2015-04-28 23:50:05] a at b dot c dot de
That RFC gives the productions
set-cookie-header = "Set-Cookie:" SP set-cookie-string
set-cookie-string = cookie-pair *( ";" SP cookie-av )
cookie-pair = cookie-name "=" cookie-value
cookie-name = token
token = <token, defined in [RFC2616], Section 2.2>
Where the latter reference defines "token" as
token = 1*<any CHAR except CTLs or separators>
CTL being ASCII control characters and "separators" being a list of punctuation marks.
So a cookie-name has to be a token, which is by definition _at least_ one character long.
------------------------------------------------------------------------
[2015-04-24 14:49:45] cmb@php.net
Consider the following statement:
setcookie('', 'value');
This constructs the following header field:
Set-Cookie: =value
This header field conforms to RFC 6265, section 4.1.1[1], because
cookie-name may be empty. So PHP allows what is permitted according
to the relevant RFC.
What's happening on the client side is not a PHP issue. The
behavior your are describing (name and value are swapped) happens
on Chrome 42.0.2311.90 m, but not on Firefox 37.0.2, for instance.
[1] <http://tools.ietf.org/html/rfc6265#section-4.1.1>
------------------------------------------------------------------------
[2015-04-24 10:55:49] florian dot schmidt dot welzow at t-online dot de
Description:
------------
If you use the script provided in "Test script" section, you''ll set a new
cookie with the name "value" and an empty value. That seems to be a false behavior, the
name of the cookie is required[1] and php should throw a fatal error, if an empty name is provided.
[1] http://php.net/manual/de/function.setcookie.php
Test script:
---------------
setcookie('', 'value', time()+10);
var_dump($_COOKIE);
Expected result:
----------------
Warning/Fatal error
Actual result:
--------------
A new cookie set with "value" as "name"
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=69523&edit=1
Thread (8 messages)