Bug #70279 [Opn->Csd]: HTTP Authorization Header is sometimes passed to newer reqeusts

From: Date: Tue, 22 Sep 2015 07:31:02 +0000
Subject: Bug #70279 [Opn->Csd]: HTTP Authorization Header is sometimes passed to newer reqeusts
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-196155@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=70279&edit=1

 ID:                 70279
 Updated by:         laruence@php.net
 Reported by:        steffenbrem at gmail dot com
 Summary:            HTTP Authorization Header is sometimes passed to
                     newer reqeusts
-Status:             Open
+Status:             Closed
 Type:               Bug
 Package:            FPM related
 Operating System:   Ubuntu Trusty
 PHP Version:        7.0Git-2015-08-16 (snap)
 Block user comment: N
 Private report:     N

 New Comment:

Automatic comment on behalf of laruence@gmail.com
Revision: http://git.php.net/?p=php-src.git;a=commit;h=1d6228b46a9440a99eca42718a5a76dcd3e0aa12
Log: Fixed bug #70279 (HTTP Authorization Header is sometimes passed to newer reqeusts)


Previous Comments:
------------------------------------------------------------------------
[2015-09-22 06:21:54] phofstetter at sensational dot ch

I can confirm now that my previous hunch was correct. This bug was introduced in
f20118aa669f9992fee8a64024e623805669391b.

The testcase given by Steffen passes with f20118aa669f9992fee8a64024e623805669391b's parent but
fails with f20118aa669f9992fee8a64024e623805669391b.

Unfortunately, the code has significantly changed since that commit was introduced, so an easy
revert will not do. I'll try to investigate a bit more in order to come up with a fix that
works on current HEAD - no promises though.

------------------------------------------------------------------------
[2015-09-22 05:34:29] phofstetter at sensational dot ch

I haven't tested this yet (currently on mobile), but if I had to guess, I would say that this
is caused by https://github.com/php/php-src/commit/f20118aa669f9992fee8a64024e623805669391b

I'll try without this commit later today and if my suspicions are correct, I'll try to
come up with a patch.

------------------------------------------------------------------------
[2015-09-09 15:37:51] steffen dot hanikel at meinfernbus dot de

I can confirm this problem running the PHP-7.0.0 branch.

Here's a very simple test case:
<?php
echo $_SERVER['HTTP_X_TEST']. "\n";
fastcgi_finish_request();

$ curl -H "X-Test: 123" http://test
123
curl http://test
123

I guess this is also an security problem.

------------------------------------------------------------------------
[2015-08-27 05:31:09] david at nnucomputerwhiz dot com

Found an easy workaround which may help with troubleshooting. 
Setting pm.max_requests = 1 in the php-fpm config prevents this from happening since each process
handles only 1 request. Obviously not a good idea in a production environment.

------------------------------------------------------------------------
[2015-08-27 02:58:01] yohgaki@php.net

Reporter states it's FPM only issue.
It sounds like request clean up is not done well in FPM SAPI.

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=70279


--
Edit this bug report at https://bugs.php.net/bug.php?id=70279&edit=1


Thread (11 messages)

« previous php.bugs (#196155) next »