Bug #78929 [Ver]: Cookie value parsing. Valid character changed into invalid. RFC6265 RFC2616

From: Date: Tue, 10 Dec 2019 14:06:04 +0000
Subject: Bug #78929 [Ver]: Cookie value parsing. Valid character changed into invalid. RFC6265 RFC2616
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-224198@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=78929&edit=1 ID: 78929 User updated by: kachalin dot alexey at gmail dot com Reported by: kachalin dot alexey at gmail dot com Summary: Cookie value parsing. Valid character changed into invalid. RFC6265 RFC2616 Status: Verified Type: Bug Package: URL related Operating System: Irrelevant PHP Version: Irrelevant Block user comment: N Private report: N New Comment: While making a good decision, please consider: 1. It's affected only for cookie set by setrawcookie() with "plus sign" inside value. The setcookie() properly encodes a "plus sign". 2. If cookie is set by external system, it's pretty hard to figure out that interaction is failed because of cookie parsing. For example: Cookie WXYZ[]^+_'abcde looks same as WXYZ[]^ _`abcde 3. PHP 7.4 released 3 weeks ago. Most probably it will have long live for several years. Some developers can write software that already need a "plus sign" fix. Previous Comments: ------------------------------------------------------------------------ [2019-12-10 11:07:02] cmb@php.net Ugh, indeed, plus signs in cookie values should be left untouched. However, the oldest PHP version which still has active support is PHP 7.3, and I have doubts that we should fix this issue for that version (not even sure about PHP 7.4) for BC reasons. ------------------------------------------------------------------------ [2019-12-08 21:09:03] kachalin dot alexey at gmail dot com The following pull request has been associated: Patch Name: Fix #78929: Fix a cookie parsing value. Switch to a php_raw_url_decode() On GitHub: https://github.com/php/php-src/pull/4989 Patch: https://github.com/php/php-src/pull/4989.patch ------------------------------------------------------------------------ [2019-12-08 18:25:16] kachalin dot alexey at gmail dot com Description: ------------ While cookie parsing PHP violate RFC standards and change valid character + "plus" x2B into invalid character space x20 How to check 1. Set cookie by php function setrawcookie(***) 2. Make sure it set correctly in browser 3. Make request with cookie and check that $_COOKIE[ COOKIE_NAME ] have cookie which plus sign was changed into space. Valid characters for value defined in RFC6265.4.1.1 Valid characters for name(token) defined in RFC6265.4.1.1. -> RFC2616.2.2 http://www.faqs.org/rfcs/rfc6265.html http://www.faqs.org/rfcs/rfc2616.html This applicable only for a value, because PHP documentation put restriction to use letters and numbers only for a cookie name. I haven't found any restriction on value and believe value should use character defined by RFC. Test script: --------------- <?php /* Run twice * At first time to set the cookie. * At second time to validate the cookie value and check an error message. */ $cookieName = 'RFC6265'; $cookieValue = '#$%&\'()*+-./0123456789<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[]^_`abcdefghijklmnopqrstuvwxyz{|}~!'; if(empty($_COOKIE[ $cookieName ]))// Set cookie for first time. { setrawcookie($cookieName, $cookieValue); } else// Compare received cookie value with set value. Should be same. Echo on error. { for($i = strlen($cookieValue)-1; $i > -1; --$i) { if(!isset($_COOKIE[ $cookieName ][ $i ])) {echo "\n<br>Cookie value symbol is lost:". $cookieValue[ $i ];} elseif($cookieValue[ $i ] != $_COOKIE[ $cookieName ][ $i ] ) {echo "\n<br>Cookie value symbol is different:".$cookieValue[ $i ];} } } Expected result: ---------------- Empty output. No error message on success execution. Actual result: -------------- If error happened message will showed with wrong or lost characters. ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=78929&edit=1

« previous php.bugs (#224198) next »