Bug #78844 [Com]: FPM does not support multiple HTTP request headers with the same name

From: Date: Wed, 20 Nov 2019 20:06:46 +0000
Subject: Bug #78844 [Com]: FPM does not support multiple HTTP request headers with the same name
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-223819@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=78844&edit=1

 ID:                 78844
 Comment by:         mikk150 at gmail dot com
 Reported by:        mikk150 at gmail dot com
 Summary:            FPM does not support multiple HTTP request headers
                     with the same name
 Status:             Open
 Type:               Bug
 Package:            FPM related
 Operating System:   Linux
 PHP Version:        7.3.11
 Block user comment: N
 Private report:     N

 New Comment:

Ah, I can see that now, I actually understood https://tools.ietf.org/html/rfc7239#section-4
incorrectly.

I undestood that
GET / HTTP/1.1
Forwarded:for=10.0.0.1;host=php.net;proto=https
Forwarded:for=20.30.40.50;host=awesome.proxy.com;proto=http
Forwarded:for=10.30.20.10;host=second.awesome.proxy.com;proto=http

would become
GET / HTTP/1.1
Forwarded:for=10.0.0.1,for=20.30.40.50,for=10.30.20.10;host=php.net,host=awesome.proxy.com,host=second.awesome.proxy.com;proto=https,proto=http,proto=http


but it actually states that each field-value(seperated by semicolon) MUST NOT occur more than once
per field-value

which means Apache is correct
GET / HTTP/1.1
Forwarded:for=10.0.0.1;host=php.net;proto=https,for=20.30.40.50;host=awesome.proxy.com;proto=http,for=10.30.20.10;host=second.awesome.proxy.com;proto=http

As this is actually correct


Previous Comments:
------------------------------------------------------------------------
[2019-11-20 19:03:45] requinix@php.net

The ability to get headers is highly dependent on the SAPI. Apache's works nicely, but php -s
is just a quick development server that is not going to be suitable for all purposes.

So really, the issue here is that php-fpm doesn't properly handle multiple headers. The HTTP
spec requires that multiple headers only be allowed when their values can be combined into
comma-separated lists, which means $_SERVER and getallheaders() are still sufficient.

------------------------------------------------------------------------
[2019-11-20 18:44:40] mikk150 at gmail dot com

summary more understandable

------------------------------------------------------------------------
[2019-11-20 17:39:23] mikk150 at gmail dot com

Description:
------------
PHP $_SERVER['HTTP_*'] superglobal and getallheaders() does not actually give all headers.
If you have multiple header lines with same name, each SAPI does totally different thing(and all of
them are wrong)

If I make request:
GET / HTTP/1.1
Forwarded: for=10.0.0.1,for=20.30.40.50;host=php.net,host=awesome.proxy.com;proto=https,proto=http
Forwarded: for=10.30.20.10;host=second.awesome.proxy.com;proto=http

I get 3 different responses based on SAPI

FPM only keeps last header
php -s only keeps first header
apache concatenates them with ,

PHP should implement new method to get all headers OR implement some class that has method to get
all headers



------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=78844&edit=1


Thread (5 messages)

« previous php.bugs (#223819) next »