Bug #76232 [Opn->Ana]: SoapClient Cookie Header Semicolon

From: Date: Thu, 19 Apr 2018 18:36:52 +0000
Subject: Bug #76232 [Opn->Ana]: SoapClient Cookie Header Semicolon
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-214812@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=76232&edit=1 ID: 76232 Updated by: cmb@php.net Reported by: philipp dot kern at datenkraft dot com Summary: SoapClient Cookie Header Semicolon -Status: Open +Status: Analyzed Type: Bug Package: SOAP related Operating System: Ubuntu 16.04.4 PHP Version: 7.0.29 Block user comment: N Private report: N New Comment: > The problem is now that we are trying to consume a web service > that unfortunately returns a "400 Bad Request" error because of > this semicolon. And it does rightly so, since according to RFC 6265[1] the semicolon acts as delimiter, not as terminator. The culprit is that the semicolon is added unconditionally directly after each cookie-pair[2]. Doing this only if (i < n-1) should solve the issue. [1] <https://tools.ietf.org/html/rfc6265> [2] <https://github.com/php/php-src/blob/PHP-7.2.5/ext/soap/php_http.c#L846> Previous Comments: ------------------------------------------------------------------------ [2018-04-18 08:31:16] philipp dot kern at datenkraft dot com Description: ------------ Hello, we have found the following problem: If you use the PHP SoapClient and the endpoint returns some cookies, the cookies get added to the subsequent requests, but there is an additional semicolon appended. Example: Cookie: testcookie1=true;testcookie2=true; According to the RFC I've read this is not neccessary. The problem is now that we are trying to consume a web service that unfortunately returns a "400 Bad Request" error because of this semicolon. Test script with an other webservice is appended to see the cookie header in the request. I have tried this with the lastest PHP versions of 7.0, 7.1 and 7.2 - same result. Thank you! Test script: --------------- $client = new SoapClient("http://ec.europa.eu/taxation_customs/vies/services/checkVatService?wsdl", array('trace' => true)); $client->__setCookie('testcookie1', 'true'); $client->__setCookie('testcookie2', 'true'); try { $response = $client->checkVat(array("countryCode" => 'TEST', "vatNumber" => 'TEST')); } catch (Exception $e) { echo "Exception caught:\n" . $e . "\n"; } $requestLoggingData = "Request:\n" . $client->__getLastRequestHeaders() . "\n\n" . $client->__getLastRequest() . "\n\n"; $requestLoggingData .= "Response:\n" . $client->__getLastResponseHeaders() . "\n\n" . $client->__getLastResponse() . "\n\n"; $requestLoggingData .= "Cookies:\n" . print_r($client->__getCookies(), true); echo $requestLoggingData; Expected result: ---------------- No semicolon is prepended in the cookie header. ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=76232&edit=1

« previous php.bugs (#214812) next »