Bug #70279 [Com]: HTTP Authorization Header is sometimes passed to newer reqeusts

From: Date: Sun, 16 Aug 2015 01:56:28 +0000
Subject: Bug #70279 [Com]: HTTP Authorization Header is sometimes passed to newer reqeusts
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-195238@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=70279&edit=1

 ID:                 70279
 Comment by:         steffenbrem at gmail dot com
 Reported by:        steffenbrem at gmail dot com
 Summary:            HTTP Authorization Header is sometimes passed to
                     newer reqeusts
 Status:             Open
 Type:               Bug
 Package:            *Web Server problem
 Operating System:   Ubuntu Trusty
 PHP Version:        7.0Git-2015-08-16 (snap)
 Block user comment: N
 Private report:     N

 New Comment:

I can confirm that this issue is not present when using PHP7 and Apache (running as php_mod). Will
try to investigate and check PHP7-FPM on other OS.


Previous Comments:
------------------------------------------------------------------------
[2015-08-16 01:04:04] steffenbrem at gmail dot com

Note that I use PHP in FastCGI mode and run it as an UNIX socket.

------------------------------------------------------------------------
[2015-08-16 00:59:31] steffenbrem at gmail dot com

Description:
------------
I have noticed a strange bug while using NGinx PPA stable and PHP7 FPM nightly build. When you send
a request containing an Authorization header and after that send a request WITHOUT an Authorization
header, PHP still thinks an Authorization header is present on the request (while it isn't).

This can cause a lot of trouble, especially since it is the Authorization header.

Expected result:
----------------
I expect that when you send a request with an authorization header and then the second time I send a
request without an Authorization header, that for that runtime there is no Authorization header set.

Actual result:
--------------
What is happening now is that the authorization header from the previous request is also passed to
the next requests. Even if you do not provide an Authorization header for the next requests.


------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=70279&edit=1


Thread (11 messages)

« previous php.bugs (#195238) next »