Edit report at https://bugs.php.net/bug.php?id=70279&edit=1
ID: 70279
Updated by: laruence@php.net
Reported by: steffenbrem at gmail dot com
Summary: HTTP Authorization Header is sometimes passed to
newer reqeusts
-Status: Open
+Status: Closed
Type: Bug
Package: FPM related
Operating System: Ubuntu Trusty
PHP Version: 7.0Git-2015-08-16 (snap)
Block user comment: N
Private report: N
New Comment:
Automatic comment on behalf of laruence@gmail.com
Revision: http://git.php.net/?p=php-src.git;a=commit;h=1d6228b46a9440a99eca42718a5a76dcd3e0aa12
Log: Fixed bug #70279 (HTTP Authorization Header is sometimes passed to newer reqeusts)
Previous Comments:
------------------------------------------------------------------------
[2015-09-22 06:21:54] phofstetter at sensational dot ch
I can confirm now that my previous hunch was correct. This bug was introduced in
f20118aa669f9992fee8a64024e623805669391b.
The testcase given by Steffen passes with f20118aa669f9992fee8a64024e623805669391b's parent but
fails with f20118aa669f9992fee8a64024e623805669391b.
Unfortunately, the code has significantly changed since that commit was introduced, so an easy
revert will not do. I'll try to investigate a bit more in order to come up with a fix that
works on current HEAD - no promises though.
------------------------------------------------------------------------
[2015-09-22 05:34:29] phofstetter at sensational dot ch
I haven't tested this yet (currently on mobile), but if I had to guess, I would say that this
is caused by https://github.com/php/php-src/commit/f20118aa669f9992fee8a64024e623805669391b
I'll try without this commit later today and if my suspicions are correct, I'll try to
come up with a patch.
------------------------------------------------------------------------
[2015-09-09 15:37:51] steffen dot hanikel at meinfernbus dot de
I can confirm this problem running the PHP-7.0.0 branch.
Here's a very simple test case:
<?php
echo $_SERVER['HTTP_X_TEST']. "\n";
fastcgi_finish_request();
$ curl -H "X-Test: 123" http://test
123
curl http://test
123
I guess this is also an security problem.
------------------------------------------------------------------------
[2015-08-27 05:31:09] david at nnucomputerwhiz dot com
Found an easy workaround which may help with troubleshooting.
Setting pm.max_requests = 1 in the php-fpm config prevents this from happening since each process
handles only 1 request. Obviously not a good idea in a production environment.
------------------------------------------------------------------------
[2015-08-27 02:58:01] yohgaki@php.net
Reporter states it's FPM only issue.
It sounds like request clean up is not done well in FPM SAPI.
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=70279
--
Edit this bug report at https://bugs.php.net/bug.php?id=70279&edit=1