Edit report at https://bugs.php.net/bug.php?id=70279&edit=1
ID: 70279
Comment by: steffenbrem at gmail dot com
Reported by: steffenbrem at gmail dot com
Summary: HTTP Authorization Header is sometimes passed to
newer reqeusts
Status: Open
Type: Bug
Package: *Web Server problem
Operating System: Ubuntu Trusty
PHP Version: 7.0Git-2015-08-16 (snap)
Block user comment: N
Private report: N
New Comment:
Note that I use PHP in FastCGI mode and run it as an UNIX socket.
Previous Comments:
------------------------------------------------------------------------
[2015-08-16 00:59:31] steffenbrem at gmail dot com
Description:
------------
I have noticed a strange bug while using NGinx PPA stable and PHP7 FPM nightly build. When you send
a request containing an Authorization header and after that send a request WITHOUT an Authorization
header, PHP still thinks an Authorization header is present on the request (while it isn't).
This can cause a lot of trouble, especially since it is the Authorization header.
Expected result:
----------------
I expect that when you send a request with an authorization header and then the second time I send a
request without an Authorization header, that for that runtime there is no Authorization header set.
Actual result:
--------------
What is happening now is that the authorization header from the previous request is also passed to
the next requests. Even if you do not provide an Authorization header for the next requests.
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=70279&edit=1