Bug #78929 [Ver->Csd]: plus signs in cookie values are converted to spaces
| From: | cmb@php.net | Date: | Thu, 12 Dec 2019 13:23:31 +0000 |
| Subject: | Bug #78929 [Ver->Csd]: plus signs in cookie values are converted to spaces | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-224242@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=78929&edit=1
ID: 78929
Updated by: cmb@php.net
Reported by: kachalin dot alexey at gmail dot com
Summary: plus signs in cookie values are converted to spaces
-Status: Verified
+Status: Closed
Type: Bug
Package: URL related
Operating System: Irrelevant
PHP Version: Irrelevant
Assigned To: cmb
Block user comment: N
Private report: N
New Comment:
Automatic comment on behalf of kachalin.alexey@gmail.com
Revision: http://git.php.net/?p=php-src.git;a=commit;h=79376ab209f61be03bbf8c1b6177c18261767da8
Log: Fix #78929: plus signs in cookie values are converted to spaces
Previous Comments:
------------------------------------------------------------------------
[2019-12-12 13:13:20] cmb@php.net
You're reasoning makes sense, so I agree that the bugfix should
target PHP 7.4
------------------------------------------------------------------------
[2019-12-10 14:06:04] kachalin dot alexey at gmail dot com
While making a good decision, please consider:
1. It's affected only for cookie set by setrawcookie() with "plus sign" inside value.
The setcookie() properly encodes a "plus sign".
2. If cookie is set by external system, it's pretty hard to figure out that interaction is
failed because of cookie parsing.
For example: Cookie WXYZ[]^+_'abcde looks same as WXYZ[]^ _`abcde
3. PHP 7.4 released 3 weeks ago. Most probably it will have long live for several years. Some
developers can write software that already need a "plus sign" fix.
------------------------------------------------------------------------
[2019-12-10 11:07:02] cmb@php.net
Ugh, indeed, plus signs in cookie values should be left untouched.
However, the oldest PHP version which still has active support is
PHP 7.3, and I have doubts that we should fix this issue for that
version (not even sure about PHP 7.4) for BC reasons.
------------------------------------------------------------------------
[2019-12-08 21:09:03] kachalin dot alexey at gmail dot com
The following pull request has been associated:
Patch Name: Fix #78929: Fix a cookie parsing value. Switch to a php_raw_url_decode()
On GitHub: https://github.com/php/php-src/pull/4989
Patch: https://github.com/php/php-src/pull/4989.patch
------------------------------------------------------------------------
[2019-12-08 18:25:16] kachalin dot alexey at gmail dot com
Description:
------------
While cookie parsing PHP violate RFC standards and change valid character + "plus" x2B
into invalid character space x20
How to check
1. Set cookie by php function setrawcookie(***)
2. Make sure it set correctly in browser
3. Make request with cookie and check that $_COOKIE[ COOKIE_NAME ] have cookie which plus sign was
changed into space.
Valid characters for value defined in RFC6265.4.1.1
Valid characters for name(token) defined in RFC6265.4.1.1. -> RFC2616.2.2
http://www.faqs.org/rfcs/rfc6265.html
http://www.faqs.org/rfcs/rfc2616.html
This applicable only for a value, because PHP documentation put restriction to use letters and
numbers only for a cookie name.
I haven't found any restriction on value and believe value should use character defined by RFC.
Test script:
---------------
<?php
/* Run twice
* At first time to set the cookie.
* At second time to validate the cookie value and check an error message.
*/
$cookieName = 'RFC6265';
$cookieValue =
'#$%&\'()*+-./0123456789<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[]^_`abcdefghijklmnopqrstuvwxyz{|}~!';
if(empty($_COOKIE[ $cookieName ]))// Set cookie for first time.
{
setrawcookie($cookieName, $cookieValue);
}
else// Compare received cookie value with set value. Should be same. Echo on error.
{
for($i = strlen($cookieValue)-1; $i > -1; --$i)
{
if(!isset($_COOKIE[ $cookieName ][ $i ]))
{echo "\n<br>Cookie value symbol is lost:". $cookieValue[ $i ];}
elseif($cookieValue[ $i ] != $_COOKIE[ $cookieName ][ $i ] )
{echo "\n<br>Cookie value symbol is different:".$cookieValue[ $i ];}
}
}
Expected result:
----------------
Empty output. No error message on success execution.
Actual result:
--------------
If error happened message will showed with wrong or lost characters.
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=78929&edit=1