Bug #75272 [NEW]: Status code is always forced to 401 when setting the WWW-Authenticate header
| From: | ramsey@php.net | Date: | Thu, 28 Sep 2017 05:57:47 +0000 |
| Subject: | Bug #75272 [NEW]: Status code is always forced to 401 when setting the WWW-Authenticate header | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-211407@lists.php.net to get a copy of this message | ||
From: ramsey
Operating system:
PHP version: master-Git-2017-09-28 (Git)
Package: *Web Server problem
Bug Type: Bug
Bug description:Status code is always forced to 401 when setting the WWW-Authenticate header
Description:
------------
When attempting to implement Bearer tokens[1] for OAuth 2, I discovered
an issue where PHP is always forcing the HTTP response status code to
401 when setting the WWW-Authenticate header. As a result, I am unable
to follow the Bearer token RFC or the HTTP Authentication RFC[2].
In RFC 6750, section 3 states:
> If the protected resource request does not include authentication
> credentials or does not contain an access token that enables access
> to the protected resource, the resource server MUST include the HTTP
> "WWW-Authenticate" response header field; it MAY include it in
> response to other conditions as well.
It goes on to describe conditions that would result in 401, 403, and
other 4xx responses, each of which may include a WWW-Authenticate
header.
In RFC 7235, section 4.1 states:
> A server generating a 401 (Unauthorized) response MUST send a
> WWW-Authenticate header field containing at least one challenge. A
> server MAY generate a WWW-Authenticate header field in other response
> messages to indicate that supplying credentials (or different
> credentials) might affect the response.
Admittedly, earlier RFCs (2616 and 2617) were ambiguous on this point,
leading many implementations to force WWW-Authenticate to 401 responses
only, and it appears PHP is one of these cases.
In main/SAPI.c[3], around lines 829-830, we see the following:
} else if (!strcasecmp(header_line, "WWW-Authenticate")) {
sapi_update_response_code(401);
I think these are the lines that force all responses setting
WWW-Authenticate header to have the 401 status code.
[1]: https://tools.ietf.org/html/rfc6750
[2]: https://tools.ietf.org/html/rfc7235
[3]:
https://github.com/php/php-src/blob/a51cb393b1accc29200e8f57ef867a6a47b2564f/main/SAPI.c#L829-L830
Test script:
---------------
<?php
header('HTTP/1.1 403 Forbidden');
header('WWW-Authenticate: Bearer realm="Foo"');
Expected result:
----------------
HTTP/1.1 403 Forbidden
Connection: close
Content-type: text/html; charset=UTF-8
Date: Thu, 28 Sep 2017 05:55:32 +0000
Host: localhost:8000
WWW-Authenticate: Bearer realm="Foo"
X-Powered-By: PHP/7.1.3
Actual result:
--------------
HTTP/1.1 401 Unauthorized
Connection: close
Content-type: text/html; charset=UTF-8
Date: Thu, 28 Sep 2017 05:55:32 +0000
Host: localhost:8000
WWW-Authenticate: Bearer realm="Foo"
X-Powered-By: PHP/7.1.3
--
Edit bug report at https://bugs.php.net/bug.php?id=75272&edit=1
--
Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=75272&r=trysnapshot54
Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=75272&r=trysnapshot55
Try a snapshot (trunk): https://bugs.php.net/fix.php?id=75272&r=trysnapshottrunk
Fixed in SVN: https://bugs.php.net/fix.php?id=75272&r=fixed
Fixed in release: https://bugs.php.net/fix.php?id=75272&r=alreadyfixed
Need backtrace: https://bugs.php.net/fix.php?id=75272&r=needtrace
Need Reproduce Script: https://bugs.php.net/fix.php?id=75272&r=needscript
Try newer version: https://bugs.php.net/fix.php?id=75272&r=oldversion
Not developer issue: https://bugs.php.net/fix.php?id=75272&r=support
Expected behavior: https://bugs.php.net/fix.php?id=75272&r=notwrong
Not enough info: https://bugs.php.net/fix.php?id=75272&r=notenoughinfo
Submitted twice: https://bugs.php.net/fix.php?id=75272&r=submittedtwice
register_globals: https://bugs.php.net/fix.php?id=75272&r=globals
PHP 4 support discontinued: https://bugs.php.net/fix.php?id=75272&r=php4
Daylight Savings: https://bugs.php.net/fix.php?id=75272&r=dst
IIS Stability: https://bugs.php.net/fix.php?id=75272&r=isapi
Install GNU Sed: https://bugs.php.net/fix.php?id=75272&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=75272&r=float
No Zend Extensions: https://bugs.php.net/fix.php?id=75272&r=nozend
MySQL Configuration Error: https://bugs.php.net/fix.php?id=75272&r=mysqlcfg