Bug #75272 [NEW]: Status code is always forced to 401 when setting the WWW-Authenticate header

From: Date: Thu, 28 Sep 2017 05:57:47 +0000
Subject: Bug #75272 [NEW]: Status code is always forced to 401 when setting the WWW-Authenticate header
Groups: php.bugs 
Request: Send a blank email to php-bugs+get-211407@lists.php.net to get a copy of this message
From: ramsey Operating system: PHP version: master-Git-2017-09-28 (Git) Package: *Web Server problem Bug Type: Bug Bug description:Status code is always forced to 401 when setting the WWW-Authenticate header Description: ------------ When attempting to implement Bearer tokens[1] for OAuth 2, I discovered an issue where PHP is always forcing the HTTP response status code to 401 when setting the WWW-Authenticate header. As a result, I am unable to follow the Bearer token RFC or the HTTP Authentication RFC[2]. In RFC 6750, section 3 states: > If the protected resource request does not include authentication > credentials or does not contain an access token that enables access > to the protected resource, the resource server MUST include the HTTP > "WWW-Authenticate" response header field; it MAY include it in > response to other conditions as well. It goes on to describe conditions that would result in 401, 403, and other 4xx responses, each of which may include a WWW-Authenticate header. In RFC 7235, section 4.1 states: > A server generating a 401 (Unauthorized) response MUST send a > WWW-Authenticate header field containing at least one challenge. A > server MAY generate a WWW-Authenticate header field in other response > messages to indicate that supplying credentials (or different > credentials) might affect the response. Admittedly, earlier RFCs (2616 and 2617) were ambiguous on this point, leading many implementations to force WWW-Authenticate to 401 responses only, and it appears PHP is one of these cases. In main/SAPI.c[3], around lines 829-830, we see the following: } else if (!strcasecmp(header_line, "WWW-Authenticate")) { sapi_update_response_code(401); I think these are the lines that force all responses setting WWW-Authenticate header to have the 401 status code. [1]: https://tools.ietf.org/html/rfc6750 [2]: https://tools.ietf.org/html/rfc7235 [3]: https://github.com/php/php-src/blob/a51cb393b1accc29200e8f57ef867a6a47b2564f/main/SAPI.c#L829-L830 Test script: --------------- <?php header('HTTP/1.1 403 Forbidden'); header('WWW-Authenticate: Bearer realm="Foo"'); Expected result: ---------------- HTTP/1.1 403 Forbidden Connection: close Content-type: text/html; charset=UTF-8 Date: Thu, 28 Sep 2017 05:55:32 +0000 Host: localhost:8000 WWW-Authenticate: Bearer realm="Foo" X-Powered-By: PHP/7.1.3 Actual result: -------------- HTTP/1.1 401 Unauthorized Connection: close Content-type: text/html; charset=UTF-8 Date: Thu, 28 Sep 2017 05:55:32 +0000 Host: localhost:8000 WWW-Authenticate: Bearer realm="Foo" X-Powered-By: PHP/7.1.3 -- Edit bug report at https://bugs.php.net/bug.php?id=75272&edit=1 -- Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=75272&r=trysnapshot54 Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=75272&r=trysnapshot55 Try a snapshot (trunk): https://bugs.php.net/fix.php?id=75272&r=trysnapshottrunk Fixed in SVN: https://bugs.php.net/fix.php?id=75272&r=fixed Fixed in release: https://bugs.php.net/fix.php?id=75272&r=alreadyfixed Need backtrace: https://bugs.php.net/fix.php?id=75272&r=needtrace Need Reproduce Script: https://bugs.php.net/fix.php?id=75272&r=needscript Try newer version: https://bugs.php.net/fix.php?id=75272&r=oldversion Not developer issue: https://bugs.php.net/fix.php?id=75272&r=support Expected behavior: https://bugs.php.net/fix.php?id=75272&r=notwrong Not enough info: https://bugs.php.net/fix.php?id=75272&r=notenoughinfo Submitted twice: https://bugs.php.net/fix.php?id=75272&r=submittedtwice register_globals: https://bugs.php.net/fix.php?id=75272&r=globals PHP 4 support discontinued: https://bugs.php.net/fix.php?id=75272&r=php4 Daylight Savings: https://bugs.php.net/fix.php?id=75272&r=dst IIS Stability: https://bugs.php.net/fix.php?id=75272&r=isapi Install GNU Sed: https://bugs.php.net/fix.php?id=75272&r=gnused Floating point limitations: https://bugs.php.net/fix.php?id=75272&r=float No Zend Extensions: https://bugs.php.net/fix.php?id=75272&r=nozend MySQL Configuration Error: https://bugs.php.net/fix.php?id=75272&r=mysqlcfg

« previous php.bugs (#211407) next »