Bug #72977 [NEW]: cURL uses wrong domain when using user names with @ sign
| From: | rlwedelschaap at gmail dot com | Date: | Tue, 30 Aug 2016 14:37:35 +0000 |
| Subject: | Bug #72977 [NEW]: cURL uses wrong domain when using user names with @ sign | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-203684@lists.php.net to get a copy of this message | ||
From: rlwedelschaap at gmail dot com
Operating system: Ubuntu 16.04 LTS
PHP version: 7.0.10
Package: cURL related
Bug Type: Bug
Bug description:cURL uses wrong domain when using user names with @ sign
Description:
------------
When using a user name and password for basic authentication in the URL
directly, cURL will try to resolve the domain from the user name when
the user name contains an @ sign instead of the actual domain.
This results in
a) requesting the wrong URL when the domain in the user name exists;
b) a "Could not resolve host" error when the domain in the user name
does not exist.
Test script:
---------------
<?php
$curl = curl_init();
curl_setopt_array( $curl, [
CURLOPT_FOLLOWLOCATION => true,
CURLOPT_FORBID_REUSE => true,
CURLOPT_FRESH_CONNECT => true,
CURLOPT_HEADER => false,
CURLOPT_HTTPHEADER => [
'Accept:
text/html,application/json,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8',
'Accept-Charset: UTF-8',
'Connection: close',
'Content-Type: charset=UTF-8',
],
CURLOPT_MAXREDIRS => 3,
CURLOPT_RETURNTRANSFER => true,
CURLOPT_SSL_VERIFYPEER => false,
CURLOPT_TIMEOUT => 30,
CURLOPT_URL =>
'http://user@domain.com:password@www.example.com/page.html',
] );
$response = curl_exec( $curl );
if ( $response !== false ) {
echo 'Completed cURL exec';
print_r( curl_getinfo( $curl ) );
} else {
echo 'Error: ' . curl_error( $curl );
print_r( curl_getinfo( $curl ) );
}
Expected result:
----------------
Completed cURL exec
Array
(
[url] => http://user@domain.com:password@www.example.com/page.html
[content_type] => text/html; charset=UTF-8
[http_code] => 200
...
)
/* $response should contain the HTML page of
http://www.example.com/page.html */
Actual result:
--------------
Completed cURL exec
Array
(
[url] => http://www.domain.com/page
[content_type] => text/html; charset=UTF-8
[http_code] => 200
...
)
/* In this scenario, $response contains the HTML page of
http://www.domain.com/page */
===== Or, when using a non-existing domain in the user name =====
Error: Could not resolve host: a-non-existing-domain.com
Array
(
[url] =>
http://user@a-non-existing-domain.com:password@www.example.com/page.html
[content_type] =>
[http_code] => 0
...
)
--
Edit bug report at https://bugs.php.net/bug.php?id=72977&edit=1
--
Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=72977&r=trysnapshot54
Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=72977&r=trysnapshot55
Try a snapshot (trunk): https://bugs.php.net/fix.php?id=72977&r=trysnapshottrunk
Fixed in SVN: https://bugs.php.net/fix.php?id=72977&r=fixed
Fixed in release: https://bugs.php.net/fix.php?id=72977&r=alreadyfixed
Need backtrace: https://bugs.php.net/fix.php?id=72977&r=needtrace
Need Reproduce Script: https://bugs.php.net/fix.php?id=72977&r=needscript
Try newer version: https://bugs.php.net/fix.php?id=72977&r=oldversion
Not developer issue: https://bugs.php.net/fix.php?id=72977&r=support
Expected behavior: https://bugs.php.net/fix.php?id=72977&r=notwrong
Not enough info: https://bugs.php.net/fix.php?id=72977&r=notenoughinfo
Submitted twice: https://bugs.php.net/fix.php?id=72977&r=submittedtwice
register_globals: https://bugs.php.net/fix.php?id=72977&r=globals
PHP 4 support discontinued: https://bugs.php.net/fix.php?id=72977&r=php4
Daylight Savings: https://bugs.php.net/fix.php?id=72977&r=dst
IIS Stability: https://bugs.php.net/fix.php?id=72977&r=isapi
Install GNU Sed: https://bugs.php.net/fix.php?id=72977&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=72977&r=float
No Zend Extensions: https://bugs.php.net/fix.php?id=72977&r=nozend
MySQL Configuration Error: https://bugs.php.net/fix.php?id=72977&r=mysqlcfg