Bug #76331 [NEW]: Location header overrides Content-Type

From: Date: Fri, 11 May 2018 16:09:41 +0000
Subject: Bug #76331 [NEW]: Location header overrides Content-Type
Groups: php.bugs 
Request: Send a blank email to php-bugs+get-215210@lists.php.net to get a copy of this message
From: Andy_Schmidt at HM-Software dot com Operating system: PHP version: 7.2.5 Package: HTTP related Bug Type: Bug Bug description:Location header overrides Content-Type Description: ------------ Setting the "Location" header will set HTTP Status to 302 by default - but ONLY if no explicit Status was set. This is a helpful/reasonable automatism. However, it will also FORCE a Content-Type of "text/html; charset=UTF-8" and adding 224 bytes to the content, disregarding any explicit Content-Type that was set (no matter if set prior or after setting "Location"). HTTP RFCs only state that the content of a redirect "SHOULD" include a forwarding link - but does NOT insist on any Content-Type, nor is this a "MUST". Every worse, PHP even overrides perfectly valid (standards-compliant) "HTML" content-types, such as "application/xhtml+xml". I believe, similar how PHP honors any explicitly set status code, it should also honor any explicitly-set Content-Type and optional supplied content, and only revert to its default Content-Type and content, if NO Content-Type was set. Test script: --------------- http_response_code( 307 ); header( 'Content-Type: application/xhtml+xml' ); header( 'Location: /transient/media/3315-234_a438fc6e0bd719703694e7bfc0b1392ecbb7a6a6_S-2.jpeg' ); header( 'Content-Type: application/xhtml+xml' ); exit; Expected result: ---------------- Response headers should be: ... Content-Length: 0 Content-Type: application/xhtml+xml ... Actual result: -------------- Response headers are: ... Content-Length: 224 Content-Type: text/html; charset=UTF-8 ... -- Edit bug report at https://bugs.php.net/bug.php?id=76331&edit=1 -- Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=76331&r=trysnapshot54 Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=76331&r=trysnapshot55 Try a snapshot (trunk): https://bugs.php.net/fix.php?id=76331&r=trysnapshottrunk Fixed in SVN: https://bugs.php.net/fix.php?id=76331&r=fixed Fixed in release: https://bugs.php.net/fix.php?id=76331&r=alreadyfixed Need backtrace: https://bugs.php.net/fix.php?id=76331&r=needtrace Need Reproduce Script: https://bugs.php.net/fix.php?id=76331&r=needscript Try newer version: https://bugs.php.net/fix.php?id=76331&r=oldversion Not developer issue: https://bugs.php.net/fix.php?id=76331&r=support Expected behavior: https://bugs.php.net/fix.php?id=76331&r=notwrong Not enough info: https://bugs.php.net/fix.php?id=76331&r=notenoughinfo Submitted twice: https://bugs.php.net/fix.php?id=76331&r=submittedtwice register_globals: https://bugs.php.net/fix.php?id=76331&r=globals PHP 4 support discontinued: https://bugs.php.net/fix.php?id=76331&r=php4 Daylight Savings: https://bugs.php.net/fix.php?id=76331&r=dst IIS Stability: https://bugs.php.net/fix.php?id=76331&r=isapi Install GNU Sed: https://bugs.php.net/fix.php?id=76331&r=gnused Floating point limitations: https://bugs.php.net/fix.php?id=76331&r=float No Zend Extensions: https://bugs.php.net/fix.php?id=76331&r=nozend MySQL Configuration Error: https://bugs.php.net/fix.php?id=76331&r=mysqlcfg

« previous php.bugs (#215210) next »