Bug #69523 [Nab]: setcookie() uses second parameter as name (first param)

From: Date: Wed, 29 Apr 2015 00:00:54 +0000
Subject: Bug #69523 [Nab]: setcookie() uses second parameter as name (first param)
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-192387@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=69523&edit=1

 ID:                 69523
 Updated by:         requinix@php.net
 Reported by:        florian dot schmidt dot welzow at t-online dot de
 Summary:            setcookie() uses second parameter as name (first
                     param)
 Status:             Not a bug
 Type:               Bug
 Package:            *Web Server problem
 Operating System:   Ubuntu 14.04.2
 PHP Version:        Irrelevant
 Assigned To:        cmb
 Block user comment: N
 Private report:     N

 New Comment:

Given that a name-less Set-Cookie header can cause problems (at the very least unexpected, probably
browser-dependent behavior), a warning and no header seems like a good idea. Would be an easy patch
too.


Previous Comments:
------------------------------------------------------------------------
[2015-04-28 23:50:05] a at b dot c dot de

That RFC gives the productions

 set-cookie-header = "Set-Cookie:" SP set-cookie-string
 set-cookie-string = cookie-pair *( ";" SP cookie-av )
 cookie-pair       = cookie-name "=" cookie-value
 cookie-name       = token
 token             = <token, defined in [RFC2616], Section 2.2>

Where the latter reference defines "token" as
       token          = 1*<any CHAR except CTLs or separators>

CTL being ASCII control characters and "separators" being a list of punctuation marks.

So a cookie-name has to be a token, which is by definition _at least_ one character long.

------------------------------------------------------------------------
[2015-04-24 14:49:45] cmb@php.net

Consider the following statement:

  setcookie('', 'value');
  
This constructs the following header field:

  Set-Cookie: =value
  
This header field conforms to RFC 6265, section 4.1.1[1], because
cookie-name may be empty. So PHP allows what is permitted according
to the relevant RFC.

What's happening on the client side is not a PHP issue. The
behavior your are describing (name and value are swapped) happens
on Chrome 42.0.2311.90 m, but not on Firefox 37.0.2, for instance.

[1] <http://tools.ietf.org/html/rfc6265#section-4.1.1>

------------------------------------------------------------------------
[2015-04-24 10:55:49] florian dot schmidt dot welzow at t-online dot de

Description:
------------
If you use the script provided in "Test script" section, you''ll set a new
cookie with the name "value" and an empty value. That seems to be a false behavior, the
name of the cookie is required[1] and php should throw a fatal error, if an empty name is provided.

[1] http://php.net/manual/de/function.setcookie.php

Test script:
---------------
setcookie('', 'value', time()+10);
var_dump($_COOKIE);

Expected result:
----------------
Warning/Fatal error

Actual result:
--------------
A new cookie set with "value" as "name"


------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=69523&edit=1


Thread (8 messages)

« previous php.bugs (#192387) next »