Bug #76232 [Opn->Ana]: SoapClient Cookie Header Semicolon
| From: | cmb@php.net | Date: | Thu, 19 Apr 2018 18:36:52 +0000 |
| Subject: | Bug #76232 [Opn->Ana]: SoapClient Cookie Header Semicolon | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-214812@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=76232&edit=1
ID: 76232
Updated by: cmb@php.net
Reported by: philipp dot kern at datenkraft dot com
Summary: SoapClient Cookie Header Semicolon
-Status: Open
+Status: Analyzed
Type: Bug
Package: SOAP related
Operating System: Ubuntu 16.04.4
PHP Version: 7.0.29
Block user comment: N
Private report: N
New Comment:
> The problem is now that we are trying to consume a web service
> that unfortunately returns a "400 Bad Request" error because of
> this semicolon.
And it does rightly so, since according to RFC 6265[1] the
semicolon acts as delimiter, not as terminator.
The culprit is that the semicolon is added unconditionally
directly after each cookie-pair[2]. Doing this only if (i < n-1)
should solve the issue.
[1] <https://tools.ietf.org/html/rfc6265>
[2] <https://github.com/php/php-src/blob/PHP-7.2.5/ext/soap/php_http.c#L846>
Previous Comments:
------------------------------------------------------------------------
[2018-04-18 08:31:16] philipp dot kern at datenkraft dot com
Description:
------------
Hello,
we have found the following problem:
If you use the PHP SoapClient and the endpoint returns some cookies, the cookies get added to the
subsequent requests, but there is an additional semicolon appended.
Example:
Cookie: testcookie1=true;testcookie2=true;
According to the RFC I've read this is not neccessary.
The problem is now that we are trying to consume a web service that unfortunately returns a
"400 Bad Request" error because of this semicolon.
Test script with an other webservice is appended to see the cookie header in the request.
I have tried this with the lastest PHP versions of 7.0, 7.1 and 7.2 - same result.
Thank you!
Test script:
---------------
$client = new SoapClient("http://ec.europa.eu/taxation_customs/vies/services/checkVatService?wsdl",
array('trace' => true));
$client->__setCookie('testcookie1', 'true');
$client->__setCookie('testcookie2', 'true');
try {
$response = $client->checkVat(array("countryCode" => 'TEST',
"vatNumber" => 'TEST'));
} catch (Exception $e) {
echo "Exception caught:\n" . $e . "\n";
}
$requestLoggingData = "Request:\n" . $client->__getLastRequestHeaders() .
"\n\n" . $client->__getLastRequest() . "\n\n";
$requestLoggingData .= "Response:\n" . $client->__getLastResponseHeaders() .
"\n\n" . $client->__getLastResponse() . "\n\n";
$requestLoggingData .= "Cookies:\n" . print_r($client->__getCookies(), true);
echo $requestLoggingData;
Expected result:
----------------
No semicolon is prepended in the cookie header.
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=76232&edit=1