Bug #78844 [Com]: FPM does not support multiple HTTP request headers with the same name
Edit report at https://bugs.php.net/bug.php?id=78844&edit=1
ID: 78844
Comment by: mikk150 at gmail dot com
Reported by: mikk150 at gmail dot com
Summary: FPM does not support multiple HTTP request headers
with the same name
Status: Open
Type: Bug
Package: FPM related
Operating System: Linux
PHP Version: 7.3.11
Block user comment: N
Private report: N
New Comment:
Ah, I can see that now, I actually understood https://tools.ietf.org/html/rfc7239#section-4
incorrectly.
I undestood that
GET / HTTP/1.1
Forwarded:for=10.0.0.1;host=php.net;proto=https
Forwarded:for=20.30.40.50;host=awesome.proxy.com;proto=http
Forwarded:for=10.30.20.10;host=second.awesome.proxy.com;proto=http
would become
GET / HTTP/1.1
Forwarded:for=10.0.0.1,for=20.30.40.50,for=10.30.20.10;host=php.net,host=awesome.proxy.com,host=second.awesome.proxy.com;proto=https,proto=http,proto=http
but it actually states that each field-value(seperated by semicolon) MUST NOT occur more than once
per field-value
which means Apache is correct
GET / HTTP/1.1
Forwarded:for=10.0.0.1;host=php.net;proto=https,for=20.30.40.50;host=awesome.proxy.com;proto=http,for=10.30.20.10;host=second.awesome.proxy.com;proto=http
As this is actually correct
Previous Comments:
------------------------------------------------------------------------
[2019-11-20 19:03:45] requinix@php.net
The ability to get headers is highly dependent on the SAPI. Apache's works nicely, but php -s
is just a quick development server that is not going to be suitable for all purposes.
So really, the issue here is that php-fpm doesn't properly handle multiple headers. The HTTP
spec requires that multiple headers only be allowed when their values can be combined into
comma-separated lists, which means $_SERVER and getallheaders() are still sufficient.
------------------------------------------------------------------------
[2019-11-20 18:44:40] mikk150 at gmail dot com
summary more understandable
------------------------------------------------------------------------
[2019-11-20 17:39:23] mikk150 at gmail dot com
Description:
------------
PHP $_SERVER['HTTP_*'] superglobal and getallheaders() does not actually give all headers.
If you have multiple header lines with same name, each SAPI does totally different thing(and all of
them are wrong)
If I make request:
GET / HTTP/1.1
Forwarded: for=10.0.0.1,for=20.30.40.50;host=php.net,host=awesome.proxy.com;proto=https,proto=http
Forwarded: for=10.30.20.10;host=second.awesome.proxy.com;proto=http
I get 3 different responses based on SAPI
FPM only keeps last header
php -s only keeps first header
apache concatenates them with ,
PHP should implement new method to get all headers OR implement some class that has method to get
all headers
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=78844&edit=1
Thread (5 messages)