Bug #70470 [Ver->Csd]: Built-in server truncates headers spanning over TCP packets
| From: | nikic@php.net | Date: | Tue, 05 Sep 2017 14:25:52 +0000 |
| Subject: | Bug #70470 [Ver->Csd]: Built-in server truncates headers spanning over TCP packets | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-210958@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=70470&edit=1
ID: 70470
Updated by: nikic@php.net
Reported by: bwoebi@php.net
Summary: Built-in server truncates headers spanning over TCP
packets
-Status: Verified
+Status: Closed
Type: Bug
Package: Built-in web server
Operating System: Irrelevant
PHP Version: 5.6.13
Block user comment: N
Private report: N
New Comment:
Automatic comment on behalf of boukevanderbijl@gmail.com
Revision: http://git.php.net/?p=php-src.git;a=commit;h=cd9d90f4d41c87494dee8ee72c7a48951213296b
Log: Fixed bug #70470
Previous Comments:
------------------------------------------------------------------------
[2017-09-04 15:08:46] bouke at shopify dot com
Hey y'all
I've made a patch that fixes this issue: https://github.com/php/php-src/pull/2736
------------------------------------------------------------------------
[2016-01-29 02:22:35] cmstlist at gmail dot com
Just wanted to add, I am experiencing this while trying to get Google's Identity Framework
("Gitkit") Quick Start for PHP working on my local computer for a school project.
https://developers.google.com/identity/toolkit/web/quickstart/php
I have a test site set up to accept Facebook or Google logins. My code is not significantly modified
from theirs aside from removing the "password" login option from the config array.
When logged in with my Facebook account, the Gitkit client-side JS library produces a 1015-character
token that it stores in a cookie. Sporadically PHP truncates the token down to 310 characters or so,
and as a result Google's OAuth2 library throws an exception (complaining the token does not
have enough segments). Within a few refreshes it works again.
When logged in with my Google account the token is only about 896 characters long. This rarely gets
truncated and thus rarely throws the same exception.
------------------------------------------------------------------------
[2015-09-11 14:35:26] bwoebi@php.net
The only solution is a different buffer⦠you may want to use a char[PHP_HTTP_MAX_HEADER_SIZE]
allocated along with the client context, then copy in and out when you need to return. I don't
really see a better way here...
check state at the end, copy if necessary⦠then on header value/name use that buffer thenâ¦
------------------------------------------------------------------------
[2015-09-11 14:35:25] bwoebi@php.net
The only solution is a different buffer⦠you may want to use a char[PHP_HTTP_MAX_HEADER_SIZE]
allocated along with the client context, then copy in and out when you need to return. I don't
really see a better way here...
check state at the end, copy if necessary⦠then on header value/name use that buffer thenâ¦
------------------------------------------------------------------------
[2015-09-11 05:51:17] laruence@php.net
actually, not only header_value, but also header name, I committed a test script here: https://github.com/php/php-src/commit/37d814b84cff3678a2e1d56ea9d3ba3c35082e13
however, I don't see a good fix in the current implementation now... :<
thanks
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=70470
--
Edit this bug report at https://bugs.php.net/bug.php?id=70470&edit=1