Bug #76331 [Nab]: Location header overrides Content-Type
| From: | cmb@php.net | Date: | Fri, 13 Sep 2019 13:47:03 +0000 |
| Subject: | Bug #76331 [Nab]: Location header overrides Content-Type | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-222736@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=76331&edit=1
ID: 76331
Updated by: cmb@php.net
Reported by: Andy_Schmidt at HM-Software dot com
Summary: Location header overrides Content-Type
Status: Not a bug
Type: Bug
Package: IIS related
Operating System: Win 2012
PHP Version: 7.2.5
Assigned To: cmb
Block user comment: N
Private report: N
New Comment:
On Windows 10 I get (regardless whether the location resource
exists or not):
HTTP/1.1 307 Temporary Redirect
Content-Type: application/xhtml+xml
Location: /cherry.jpg
Server: Microsoft-IIS/10.0
X-Powered-By: PHP/7.2.22
Date: Fri, 13 Sep 2019 13:41:05 GMT
Content-Length: 0
Previous Comments:
------------------------------------------------------------------------
[2019-09-13 13:16:43] Andy_Schmidt at HM-Software dot com
Indeed, I do suspect the same (I had come across that reference as well last night so I did some
targeted testing). However, it actually does NOT seem to be limited to FastCGI, it even happens if I
configure IIS to process .PHP through IIS' standard CGI interface to "php-cgi.exe",
rather than IIS' FastCGI ISAPI.
I'd be interested to see the headers that Win 2016 generated for my reference.
But I do agree that the injected HTML content, type and length appears to be injected by IIS
(possibly up to 2012), not PHP.
------------------------------------------------------------------------
[2019-09-13 10:17:11] cmb@php.net
Well, it seems that this is a known issue that affects older IIS
versions[1], and I don't think we can do anything about it.
[1] <https://forums.iis.net/t/1209573.aspx#2082988>
------------------------------------------------------------------------
[2019-09-13 00:14:39] Andy_Schmidt at HM-Software dot com
PS - if I intentionally "garble" the "Location:" header, THEN the Content-Type
and Content-Length headers remain unaltered:
HTTP/1.1 307 Temporary Redirect
Content-Type: application/xhtml+xml
Server: Microsoft-IIS/8.5
X-Powered-By: PHP/7.3.8
X-Location: /62044-206/9edf47546f10b3f4d0b2e9420c5d74f5f2343d53/D.jpeg
X-Powered-By: ASP.NET
Date: Fri, 13 Sep 2019 00:11:01 GMT
Content-Length: 0
Naturally, it won't actually redirect, for lack of a new location, but at least it demonstrates
that the issue is not based on some "configuration" detail, but rather triggered by the
existence of a "Location:" request header.
------------------------------------------------------------------------
[2019-09-12 23:48:51] Andy_Schmidt at HM-Software dot com
No error page for 307 configured at all.
Sorry, have no IIS 10 to test.
Just reran my test with 7.3.8 under IIS 8.5 - tried both with FastCGI and even had it run native CGI
through php-cgi-.exe. I inspected the raw headers in Firefox' Network Tools to confirm that
both the Content-Type and Content-Length is "altered".
HTTP/1.1 307 Temporary Redirect
Content-Type: text/html; charset=UTF-8
Location: /62044-206/9edf47546f10b3f4d0b2e9420c5d74f5f2343d53/D.jpeg
Server: Microsoft-IIS/8.5
X-Powered-By: PHP/7.3.8
X-Powered-By: ASP.NET
Date: Thu, 12 Sep 2019 23:38:27 GMT
Content-Length: 231
------------------------------------------------------------------------
[2019-09-12 09:01:33] cmb@php.net
I cannot reproduce this with IIS 10 FCGI (PHP 7.2.22).
> Because, NOT ONLY does the system override the "Content-Type",
> it actually injects a default HTML content with the title
> "Document Moved", and an H1 of "Object Moved" and a body of "This
> document may be found here".
This sounds like a Webserver configuration issue. Is there,
maybe, an error page defined for 307?
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=76331
--
Edit this bug report at https://bugs.php.net/bug.php?id=76331&edit=1