Bug #78207 [Opn->Nab]: setrawcookie does not not behave like setcookie when overwriting
| From: | daverandom@php.net | Date: | Tue, 25 Jun 2019 15:31:23 +0000 |
| Subject: | Bug #78207 [Opn->Nab]: setrawcookie does not not behave like setcookie when overwriting | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-221482@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=78207&edit=1
ID: 78207
Updated by: daverandom@php.net
Reported by: nico at billiotte dot fr
Summary: setrawcookie does not not behave like setcookie when
overwriting
-Status: Open
+Status: Not a bug
Type: Bug
Package: Unknown/Other Function
Operating System: OSX + linux
PHP Version: 7.3.6
Block user comment: N
Private report: N
New Comment:
Thank you for taking the time to write to us, but this is not
a bug. Please double-check the documentation available at
http://www.php.net/manual/ and the instructions on how to
report
a bug at http://bugs.php.net/how-to-report.php
This is the correct, intended behaviour - it is caused by the specific value for the cookie, rather
than the general behaviour of the function.
If you turn on error reporting, you will find that the following warning is emitted:
> Warning: Cookie values cannot contain any of the following ',; \t\r\n\013\014' in ...
This is due to the syntax of the Cookie header in the HTTP protocol. The solution to this problem is
to use setcookie() instead of setrawcookie(), which will correctly encode the values.
This issue arises because the JSON generated by the first request does not contain a comma, the
second request adds a second element separated by a comma.
Previous Comments:
------------------------------------------------------------------------
[2019-06-25 15:12:25] nico at billiotte dot fr
Description:
------------
---
From manual page: https://php.net/function.setrawcookie
---
Test script:
---------------
$id = $_REQUEST['id'];
$val = $_REQUEST['val'];
if( isset($_COOKIE['testcookie']) ){
$cookie = json_decode($_COOKIE['testcookie'], true);
}
$moncookie[$id] = $val;
setrawcookie('testcookie', json_encode($cookie), 0, '/');
Expected result:
----------------
send id = 1 & val = "foo"
cookie = {1:foo} -> correct
then resend id = 2 & val = "bar"
cookie should contain {1:foo, 2:bar}
Actual result:
--------------
the cookie remains nothing changes
{1:foo} -> not correct
change setrawcookie by setcookie and add urldecode() and everything is fine you can
"update" the cookie
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=78207&edit=1