Bug #71541 [NEW]: Script invoked multiple times if PATH_INFO present
| From: | lobbotermey at gmail dot com | Date: | Sun, 07 Feb 2016 10:16:48 +0000 |
| Subject: | Bug #71541 [NEW]: Script invoked multiple times if PATH_INFO present | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-199086@lists.php.net to get a copy of this message | ||
From: lobbotermey at gmail dot com
Operating system: Ubuntu 14.04.3
PHP version: Irrelevant
Package: URL related
Bug Type: Bug
Bug description:Script invoked multiple times if PATH_INFO present
Description:
------------
The test script generates a simple HTML document containing the $_SERVER
PATH_INFO and SCRIPT_FILENAME variables and writes the same to a file
called "test".
This appears to work as expected and, provided you invoke it with a
conventional URI, eg "http://example.com/foo.php", everything is fine.
However, if you invoke it with a URI that includes path info - for
example "http://example.com/foo.php/"
(note trailing "/") - although the
echo to the browser appears to work, if you look at the "test" file, you
see that the script has in fact been run multiple times.
The problem appears to be related to the stylesheet; the script is
invoked once as "http://example.com/foo.php/" and then a second
time as
"http://example.com/foo.php/default.css",
presumably as the browser
attempts to fetch the stylesheet and the server interprets it as a call
to the same script with different path info and invokes PHP again.
Im not sure exactly where the problem lies here. PHP, Apache and the
browser (tried with both FF44 and Chrome43) all appear to be behaving as
designed, but the result is still broken.
At the very least, this should probably be documented somewhere.
Test script:
---------------
// WARNING: this will write a file called "test"
echo "<!doctype html>\n";
echo "<html lang=en>\n";
echo "<head>\n";
echo "<meta charset=utf-8>\n";
echo "<link rel=StyleSheet href=default.css type=text/css>\n";
echo "<title>Test PATH_INFO bug</title>\n";
echo "</head>\n";
echo "<body>\n";
echo "<p>Server SCRIPT_FILENAME is
'{$_SERVER['SCRIPT_FILENAME']}'.</p>\n";
echo "<p>Server PATH_INFO is
'{$_SERVER['PATH_INFO']}'.</p>\n";
if (($fh = fopen('test', 'a')) !== FALSE)
{
fwrite($fh, $_SERVER['SCRIPT_FILENAME'] . "\n" .
$_SERVER['PATH_INFO']
. "\n");
fclose($fh);
}
echo "</body>\n";
echo "</html>\n";
Expected result:
----------------
The "test" file should contain:
/$DOCROOT/test.php
/
Actual result:
--------------
The "test" file actually contains:
/$DOCROOT/test.php
/
/$DOCROOT/test.php
/default.css
--
Edit bug report at https://bugs.php.net/bug.php?id=71541&edit=1
--
Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=71541&r=trysnapshot54
Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=71541&r=trysnapshot55
Try a snapshot (trunk): https://bugs.php.net/fix.php?id=71541&r=trysnapshottrunk
Fixed in SVN: https://bugs.php.net/fix.php?id=71541&r=fixed
Fixed in release: https://bugs.php.net/fix.php?id=71541&r=alreadyfixed
Need backtrace: https://bugs.php.net/fix.php?id=71541&r=needtrace
Need Reproduce Script: https://bugs.php.net/fix.php?id=71541&r=needscript
Try newer version: https://bugs.php.net/fix.php?id=71541&r=oldversion
Not developer issue: https://bugs.php.net/fix.php?id=71541&r=support
Expected behavior: https://bugs.php.net/fix.php?id=71541&r=notwrong
Not enough info: https://bugs.php.net/fix.php?id=71541&r=notenoughinfo
Submitted twice: https://bugs.php.net/fix.php?id=71541&r=submittedtwice
register_globals: https://bugs.php.net/fix.php?id=71541&r=globals
PHP 4 support discontinued: https://bugs.php.net/fix.php?id=71541&r=php4
Daylight Savings: https://bugs.php.net/fix.php?id=71541&r=dst
IIS Stability: https://bugs.php.net/fix.php?id=71541&r=isapi
Install GNU Sed: https://bugs.php.net/fix.php?id=71541&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=71541&r=float
No Zend Extensions: https://bugs.php.net/fix.php?id=71541&r=nozend
MySQL Configuration Error: https://bugs.php.net/fix.php?id=71541&r=mysqlcfg