Bug #76331 [Opn]: Location header overrides Content-Type

From: Date: Fri, 11 May 2018 21:20:48 +0000
Subject: Bug #76331 [Opn]: Location header overrides Content-Type
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-215225@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=76331&edit=1 ID: 76331 Updated by: cmb@php.net Reported by: Andy_Schmidt at HM-Software dot com Summary: Location header overrides Content-Type Status: Open Type: Bug Package: HTTP related PHP Version: 7.2.5 Block user comment: N Private report: N New Comment: > […] one yet need to show me any client not following a http > redirect unconditional <https://curl.haxx.se/> does not even follow redirects by default. Anyway, this bug tracker is most certainly not the appropriate place to discuss the reasonableness of Internet standards and possibly divergent behavior of clients. Please let's stick to the issue at hand, which is that the supplied Content-Type header is overridden for apparently no good reason. Previous Comments: ------------------------------------------------------------------------ [2018-05-11 20:57:46] spam2 at rhsoft dot net WTF - especially after a POST request succeeded automatic redirects to a confirmation page are common to avoid multiple submits and one yet need to show me any client not following a http redirect unconditional ------------------------------------------------------------------------ [2018-05-11 20:55:28] cmb@php.net > SAPI is standard IIS 8.5 FastCGI. Thanks. So this is likely an (F)CGI issue (I've tested with Apache mod_php). ------------------------------------------------------------------------ [2018-05-11 20:42:03] Andy_Schmidt at HM-Software dot com >> spam2@rhsoft.net: ...should not contain any http body at all << Automatic redirection is NOT a requirement, moreover, inclusion of a payload IS explicitly mentioned as being common - exactly the opposite of your opinion. Please note https://tools.ietf.org/html/rfc7231#section-6.4.2: "The server SHOULD generate a Location header field in the response containing a preferred URI reference for the new permanent URI. The user agent MAY use the Location field value for automatic redirection. The server's response payload usually contains a short hypertext note with a hyperlink to the new URI(s)." ------------------------------------------------------------------------ [2018-05-11 20:34:08] Andy_Schmidt at HM-Software dot com PS: It is also possible to use redirect status 301/302/307 and NOT include a "Location: " header. I've heard of cases where this is used to indicate that the current URL is no longer valid, but automatic forwarding is NOT wanted. Instead, content is displayed that might offer up a number of alternative links. And, of course, that content might be served up in whatever Content-Type DIFFERENT from the "text/html" that currently is being hard-substituted. ------------------------------------------------------------------------ [2018-05-11 20:30:37] Andy_Schmidt at HM-Software dot com >> spam2@rhsoft.net: ...should not contain any http body at all << I respect your opinion, however, this is governed by RFCs, which states precisely the OPPOSITE: "Unless the request method was HEAD, the entity of the response SHOULD contain a short hypertext note with a hyperlink to the new URI(s)." (https://www.w3.org/Protocols/rfc2616/rfc2616-sec10.html) This allows for clients that do NOT perform an automatic redirect. In fact there are scenarios (e.g., request was not "GET" or "HEAD") where the automatic redirect MUST NO occur! ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=76331 -- Edit this bug report at https://bugs.php.net/bug.php?id=76331&edit=1

« previous php.bugs (#215225) next »