Bug #69523 [Fbk->Csd]: setcookie() uses second parameter as name (first param)

From: Date: Tue, 12 May 2015 08:50:53 +0000
Subject: Bug #69523 [Fbk->Csd]: setcookie() uses second parameter as name (first param)
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-192629@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=69523&edit=1

 ID:                 69523
 Updated by:         jpauli@php.net
 Reported by:        florian dot schmidt dot welzow at t-online dot de
 Summary:            setcookie() uses second parameter as name (first
                     param)
-Status:             Feedback
+Status:             Closed
 Type:               Bug
 Package:            *Web Server problem
 Operating System:   Ubuntu 14.04.2
 PHP Version:        Irrelevant
-Assigned To:        
+Assigned To:        jpauli
 Block user comment: N
 Private report:     N

 New Comment:

Please try using this snapshot:

  http://snaps.php.net/php-trunk-latest.tar.gz
 
For Windows:

  http://windows.php.net/snapshots/




Previous Comments:
------------------------------------------------------------------------
[2015-05-12 08:50:07] jpauli@php.net

Please try using this snapshot:

  http://snaps.php.net/php-trunk-latest.tar.gz
 
For Windows:

  http://windows.php.net/snapshots/

I merged the PR with a WARNING error, we still can change it to a NOTICE in the future, if someone
objects.

------------------------------------------------------------------------
[2015-04-29 00:39:23] cmb@php.net

> cookie-name       = token
> token          = 1*<any CHAR except CTLs or separators>

Obviously, you're right and I was mistaken.

> [...] a warning and no header seems like a good idea.

A notice might suffice, and it may be considered to check the
cookie name against the specified grammar (not only hinting at
empty names).

------------------------------------------------------------------------
[2015-04-29 00:00:53] requinix@php.net

Given that a name-less Set-Cookie header can cause problems (at the very least unexpected, probably
browser-dependent behavior), a warning and no header seems like a good idea. Would be an easy patch
too.

------------------------------------------------------------------------
[2015-04-28 23:50:05] a at b dot c dot de

That RFC gives the productions

 set-cookie-header = "Set-Cookie:" SP set-cookie-string
 set-cookie-string = cookie-pair *( ";" SP cookie-av )
 cookie-pair       = cookie-name "=" cookie-value
 cookie-name       = token
 token             = <token, defined in [RFC2616], Section 2.2>

Where the latter reference defines "token" as
       token          = 1*<any CHAR except CTLs or separators>

CTL being ASCII control characters and "separators" being a list of punctuation marks.

So a cookie-name has to be a token, which is by definition _at least_ one character long.

------------------------------------------------------------------------
[2015-04-24 14:49:45] cmb@php.net

Consider the following statement:

  setcookie('', 'value');
  
This constructs the following header field:

  Set-Cookie: =value
  
This header field conforms to RFC 6265, section 4.1.1[1], because
cookie-name may be empty. So PHP allows what is permitted according
to the relevant RFC.

What's happening on the client side is not a PHP issue. The
behavior your are describing (name and value are swapped) happens
on Chrome 42.0.2311.90 m, but not on Firefox 37.0.2, for instance.

[1] <http://tools.ietf.org/html/rfc6265#section-4.1.1>

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=69523


--
Edit this bug report at https://bugs.php.net/bug.php?id=69523&edit=1


Thread (8 messages)

« previous php.bugs (#192629) next »