Bug #74796 [Com]: Requests through https:// with http proxy set altering default context
| From: | anrdaemon at freemail dot ru | Date: | Thu, 22 Jun 2017 11:42:42 +0000 |
| Subject: | Bug #74796 [Com]: Requests through https:// with http proxy set altering default context | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-209626@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=74796&edit=1
ID: 74796
Comment by: anrdaemon at freemail dot ru
Reported by: anrdaemon at freemail dot ru
Summary: Requests through https:// with http proxy set
altering default context
Status: Open
Type: Bug
Package: Streams related
Operating System: Windows, Linux
PHP Version: 7.1.6
Block user comment: N
Private report: N
New Comment:
And I just found out that settings "https" context has no effect.
Both "https://" and "http://" URL's fall into "http" context.
WHY?â¦
Previous Comments:
------------------------------------------------------------------------
[2017-06-22 11:06:32] anrdaemon at freemail dot ru
Description:
------------
Adding http proxy to default stream context making addressing different HTTPS domains in the same
script impossible.
First request to HTTPS site after associating a http proxy sets ssl context to a single peer name
and requests to any other domain will fail.
Tested with 7.1.6 and 5.6.30 on Windows and Ubuntu Linux.
Test script:
---------------
<?php
stream_context_set_default([
"https" => [
"proxy" => "tcp://proxy:3128"
],
]);
var_dump(stream_context_get_options(stream_context_get_default()));
file_get_contents("https://www.google.com/");
// fine
var_dump(stream_context_get_options(stream_context_get_default()));
file_get_contents("https://www.yahoo.com/"); //
fine
var_dump(stream_context_get_options(stream_context_get_default()));
stream_context_set_default([
"http" => [
"proxy" => "tcp://proxy:3128"
],
]);
var_dump(stream_context_get_options(stream_context_get_default()));
file_get_contents("https://www.google.com/");
// fine
var_dump(stream_context_get_options(stream_context_get_default())); // ssl:peer_name is set
file_get_contents("https://www.yahoo.com/"); //
Peer certificate CN=
*.www.yahoo.com' did not match expected
CN=www.google.com' in ...
var_dump(stream_context_get_options(stream_context_get_default()));
Expected result:
----------------
array(1) {
["https"]=>
array(1) {
["proxy"]=>
string(16) "tcp://proxy:3128"
}
}
array(1) {
["https"]=>
array(1) {
["proxy"]=>
string(16) "tcp://proxy:3128"
}
}
array(1) {
["https"]=>
array(1) {
["proxy"]=>
string(16) "tcp://proxy:3128"
}
}
array(2) {
["https"]=>
array(1) {
["proxy"]=>
string(16) "tcp://proxy:3128"
}
["http"]=>
array(1) {
["proxy"]=>
string(16) "tcp://proxy:3128"
}
}
array(3) {
["https"]=>
array(1) {
["proxy"]=>
string(16) "tcp://proxy:3128"
}
["http"]=>
array(1) {
["proxy"]=>
string(16) "tcp://proxy:3128"
}
}
array(3) {
["https"]=>
array(1) {
["proxy"]=>
string(16) "tcp://proxy:3128"
}
["http"]=>
array(1) {
["proxy"]=>
string(16) "tcp://proxy:3128"
}
}
Actual result:
--------------
array(1) {
["https"]=>
array(1) {
["proxy"]=>
string(16) "tcp://proxy:3128"
}
}
array(1) {
["https"]=>
array(1) {
["proxy"]=>
string(16) "tcp://proxy:3128"
}
}
array(1) {
["https"]=>
array(1) {
["proxy"]=>
string(16) "tcp://proxy:3128"
}
}
array(2) {
["https"]=>
array(1) {
["proxy"]=>
string(16) "tcp://proxy:3128"
}
["http"]=>
array(1) {
["proxy"]=>
string(16) "tcp://proxy:3128"
}
}
array(3) {
["https"]=>
array(1) {
["proxy"]=>
string(16) "tcp://proxy:3128"
}
["http"]=>
array(1) {
["proxy"]=>
string(16) "tcp://proxy:3128"
}
["ssl"]=>
array(1) {
["peer_name"]=>
string(14) "www.google.com"
}
}
PHP Warning: file_get_contents(): Peer certificate CN=*.www.yahoo.com' did not match
expected CN=www.google.com' in test.php on line 21
PHP Warning: file_get_contents(https://www.yahoo.com/): failed to open stream: Cannot connect to
HTTPS server through proxy in test.php on line 21
array(3) {
["https"]=>
array(1) {
["proxy"]=>
string(16) "tcp://proxy:3128"
}
["http"]=>
array(1) {
["proxy"]=>
string(16) "tcp://proxy:3128"
}
["ssl"]=>
array(1) {
["peer_name"]=>
string(14) "www.google.com"
}
}
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=74796&edit=1