Req #74535 [Com]: please warn users when implicit Location: HTTP status override triggers
| From: | remy at lebeausoftware dot org | Date: | Wed, 03 May 2017 19:13:41 +0000 |
| Subject: | Req #74535 [Com]: please warn users when implicit Location: HTTP status override triggers | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-208944@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=74535&edit=1
ID: 74535
Comment by: remy at lebeausoftware dot org
Reported by: joy+php at entuzijast dot net
Summary: please warn users when implicit Location: HTTP
status override triggers
Status: Open
Type: Feature/Change Request
Package: HTTP related
PHP Version: Irrelevant
Block user comment: N
Private report: N
New Comment:
"The 'Location' header is treated as a redirect only in 201 and 3xx". Sorry, I
meant 3xx only (not including 304, BTW). In fact, case in point, 201 defines 'Location; for
non-redirect purposes (the new URL of the created resource). So can other status codes as desired.
'Location' can have semantic meaning in 202 (a status monitor URL for the pending
operation), for instance.
Previous Comments:
------------------------------------------------------------------------
[2017-05-03 19:09:13] remy at lebeausoftware dot org
Replacing a previously established status code with 302 is NOT conformant to RFC 2616. Nowhere does
that RFC say that the 'Location' header can't be used in status codes other than 201
and 3xx. It would make sense for header() to *default* the 'Location' header to 302 if a
status code has not been assigned yet, but it certainly should not overwrite an existing status
code, or at least should only overwrite 200. The 'Location' header is treated as a
redirect only in 201 and 3xx, but it can be used by other status codes for other purposes besides
redirects.
------------------------------------------------------------------------
[2017-05-03 13:27:31] joy+php at entuzijast dot net
Description:
------------
Hi,
An aspect of this bug was previously reported at https://bugs.php.net/bug.php?id=70273
When you run:
header("HTTP/1.1 202 Accepted");
header("Location: whatever");
...this second header will invoke the function which will replace the user-defined status code (202
in this example) with a 302. This is fine, as it is conformant to RFC 2616, but there should really
be a warning emitted in the logs to tell the user that their input was explicitly ignored. For
example, say "PHP Warning: Location header incompatible with HTTP/1.1 202 Accepted, falling
back to HTTP/1.1 302 Found"
TIA.
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=74535&edit=1