Bug #78929 [NEW]: Cookie value parsing. Valid character changed into invalid. RFC6265 RFC2616

From: Date: Sun, 08 Dec 2019 18:25:16 +0000
Subject: Bug #78929 [NEW]: Cookie value parsing. Valid character changed into invalid. RFC6265 RFC2616
Groups: php.bugs 
Request: Send a blank email to php-bugs+get-224130@lists.php.net to get a copy of this message
From: kachalin dot alexey at gmail dot com Operating system: Irrelevant PHP version: Irrelevant Package: URL related Bug Type: Bug Bug description:Cookie value parsing. Valid character changed into invalid. RFC6265 RFC2616 Description: ------------ While cookie parsing PHP violate RFC standards and change valid character + "plus" x2B into invalid character space x20 How to check 1. Set cookie by php function setrawcookie(***) 2. Make sure it set correctly in browser 3. Make request with cookie and check that $_COOKIE[ COOKIE_NAME ] have cookie which plus sign was changed into space. Valid characters for value defined in RFC6265.4.1.1 Valid characters for name(token) defined in RFC6265.4.1.1. -> RFC2616.2.2 http://www.faqs.org/rfcs/rfc6265.html http://www.faqs.org/rfcs/rfc2616.html This applicable only for a value, because PHP documentation put restriction to use letters and numbers only for a cookie name. I haven't found any restriction on value and believe value should use character defined by RFC. Test script: --------------- <?php /* Run twice * At first time to set the cookie. * At second time to validate the cookie value and check an error message. */ $cookieName = 'RFC6265'; $cookieValue = '#$%&\'()*+-./0123456789<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[]^_`abcdefghijklmnopqrstuvwxyz{|}~!'; if(empty($_COOKIE[ $cookieName ]))// Set cookie for first time. { setrawcookie($cookieName, $cookieValue); } else// Compare received cookie value with set value. Should be same. Echo on error. { for($i = strlen($cookieValue)-1; $i > -1; --$i) { if(!isset($_COOKIE[ $cookieName ][ $i ])) {echo "\n<br>Cookie value symbol is lost:". $cookieValue[ $i ];} elseif($cookieValue[ $i ] != $_COOKIE[ $cookieName ][ $i ] ) {echo "\n<br>Cookie value symbol is different:".$cookieValue[ $i ];} } } Expected result: ---------------- Empty output. No error message on success execution. Actual result: -------------- If error happened message will showed with wrong or lost characters. -- Edit bug report at https://bugs.php.net/bug.php?id=78929&edit=1 -- Fix committed: https://bugs.php.net/fix.php?id=78929&r=fixed Fixed in release: https://bugs.php.net/fix.php?id=78929&r=alreadyfixed Need backtrace: https://bugs.php.net/fix.php?id=78929&r=needtrace Need Reproduce Script: https://bugs.php.net/fix.php?id=78929&r=needscript Try newer version: https://bugs.php.net/fix.php?id=78929&r=oldversion Not developer issue: https://bugs.php.net/fix.php?id=78929&r=support Expected behavior: https://bugs.php.net/fix.php?id=78929&r=notwrong Not enough info: https://bugs.php.net/fix.php?id=78929&r=notenoughinfo Submitted twice: https://bugs.php.net/fix.php?id=78929&r=submittedtwice register_globals: https://bugs.php.net/fix.php?id=78929&r=globals PHP version support discontinued: https://bugs.php.net/fix.php?id=78929&r=phptooold Daylight Savings: https://bugs.php.net/fix.php?id=78929&r=dst IIS Stability: https://bugs.php.net/fix.php?id=78929&r=isapi Install GNU Sed: https://bugs.php.net/fix.php?id=78929&r=gnused Floating point limitations: https://bugs.php.net/fix.php?id=78929&r=float No Zend Extensions: https://bugs.php.net/fix.php?id=78929&r=nozend MySQL Configuration Error: https://bugs.php.net/fix.php?id=78929&r=mysqlcfg

« previous php.bugs (#224130) next »