Req #74535 [Com]: please warn users when implicit Location: HTTP status override triggers

From: Date: Wed, 03 May 2017 19:13:41 +0000
Subject: Req #74535 [Com]: please warn users when implicit Location: HTTP status override triggers
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-208944@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=74535&edit=1 ID: 74535 Comment by: remy at lebeausoftware dot org Reported by: joy+php at entuzijast dot net Summary: please warn users when implicit Location: HTTP status override triggers Status: Open Type: Feature/Change Request Package: HTTP related PHP Version: Irrelevant Block user comment: N Private report: N New Comment: "The 'Location' header is treated as a redirect only in 201 and 3xx". Sorry, I meant 3xx only (not including 304, BTW). In fact, case in point, 201 defines 'Location; for non-redirect purposes (the new URL of the created resource). So can other status codes as desired. 'Location' can have semantic meaning in 202 (a status monitor URL for the pending operation), for instance. Previous Comments: ------------------------------------------------------------------------ [2017-05-03 19:09:13] remy at lebeausoftware dot org Replacing a previously established status code with 302 is NOT conformant to RFC 2616. Nowhere does that RFC say that the 'Location' header can't be used in status codes other than 201 and 3xx. It would make sense for header() to *default* the 'Location' header to 302 if a status code has not been assigned yet, but it certainly should not overwrite an existing status code, or at least should only overwrite 200. The 'Location' header is treated as a redirect only in 201 and 3xx, but it can be used by other status codes for other purposes besides redirects. ------------------------------------------------------------------------ [2017-05-03 13:27:31] joy+php at entuzijast dot net Description: ------------ Hi, An aspect of this bug was previously reported at https://bugs.php.net/bug.php?id=70273 When you run: header("HTTP/1.1 202 Accepted"); header("Location: whatever"); ...this second header will invoke the function which will replace the user-defined status code (202 in this example) with a 302. This is fine, as it is conformant to RFC 2616, but there should really be a warning emitted in the logs to tell the user that their input was explicitly ignored. For example, say "PHP Warning: Location header incompatible with HTTP/1.1 202 Accepted, falling back to HTTP/1.1 302 Found" TIA. ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=74535&edit=1

« previous php.bugs (#208944) next »