Req #74535 [Com]: please warn users when implicit Location: HTTP status override triggers

From: Date: Wed, 03 May 2017 19:09:17 +0000
Subject: Req #74535 [Com]: please warn users when implicit Location: HTTP status override triggers
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-208943@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=74535&edit=1

 ID:                 74535
 Comment by:         remy at lebeausoftware dot org
 Reported by:        joy+php at entuzijast dot net
 Summary:            please warn users when implicit Location: HTTP
                     status override triggers
 Status:             Open
 Type:               Feature/Change Request
 Package:            HTTP related
 PHP Version:        Irrelevant
 Block user comment: N
 Private report:     N

 New Comment:

Replacing a previously established status code with 302 is NOT conformant to RFC 2616.  Nowhere does
that RFC say that the 'Location' header can't be used in status codes other than 201
and 3xx.  It would make sense for header() to *default* the 'Location' header to 302 if a
status code has not been assigned yet, but it certainly should not overwrite an existing status
code, or at least should only overwrite 200.  The 'Location' header is treated as a
redirect only in 201 and 3xx, but it can be used by other status codes for other purposes besides
redirects.


Previous Comments:
------------------------------------------------------------------------
[2017-05-03 13:27:31] joy+php at entuzijast dot net

Description:
------------
Hi,

An aspect of this bug was previously reported at https://bugs.php.net/bug.php?id=70273

When you run:

header("HTTP/1.1 202 Accepted");
header("Location: whatever");

...this second header will invoke the function which will replace the user-defined status code (202
in this example) with a 302. This is fine, as it is conformant to RFC 2616, but there should really
be a warning emitted in the logs to tell the user that their input was explicitly ignored. For
example, say "PHP Warning: Location header incompatible with HTTP/1.1 202 Accepted, falling
back to HTTP/1.1 302 Found"

TIA.




------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=74535&edit=1


Thread (3 messages)

« previous php.bugs (#208943) next »