Bug #79004 [Com]: CURLFile's 3rd argument doesn't honor emptystring
| From: | divinity76 at gmail dot com | Date: | Fri, 20 Dec 2019 00:20:29 +0000 |
| Subject: | Bug #79004 [Com]: CURLFile's 3rd argument doesn't honor emptystring | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-224432@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=79004&edit=1
ID: 79004
Comment by: divinity76 at gmail dot com
Reported by: divinity76 at gmail dot com
Summary: CURLFile's 3rd argument doesn't honor emptystring
Status: Open
Type: Bug
Package: cURL related
Operating System: Ubuntu 18.04
PHP Version: 7.2.26
Block user comment: N
Private report: N
New Comment:
i suppose it's possible that the on-disk location of CURLFile's argument could be
considered sensitive information, and thus it's inappropriate disclosure here may be a security
issue, idk but food for thought
Previous Comments:
------------------------------------------------------------------------
[2019-12-20 00:13:49] divinity76 at gmail dot com
change to curl-related (couldn't find "curl related" when creating the issue for some
reason)
------------------------------------------------------------------------
[2019-12-20 00:12:28] divinity76 at gmail dot com
Description:
------------
if you give CURLFile's an empty string as the third argument, it will in fact swap out the
empty string with the first argument!
that makes porting this curl command rather difficult:
curl -F "uploadManifest={json};type=application/json" http://127.0.0.1:9999/
i guess it's debatable weather emptystring should remove the filename header entirely (like
CURLOPT_HTTPHEADER does, for example to remove libcurl-generated "Expect: 100-continue"
headers, set CURLOPT_HTTPHEADER=>array("Except: "), and the Expect header won't be
generated at all), or if it should literally send filename=""
(but my personal opinion is that it should work the same as CURLOPT_HTTPHEADER, eg remove the
filename header entirely), but whatever the right action is, it's certainly not the current
action of replacing it with the on-disk file-location, and that's what it's currently
doing. (maybe that would be ok if argument 3 is null, i don't know, but it's not
appropriate if the 3rd argument is emptystring, the programmer specifically asked for an empty
filename, and now doesn't get one.)
Test script:
---------------
<?php
$stupid_workaround_fileh = tmpfile();
$stupid_workaround_filef = stream_get_meta_data($stupid_workaround_fileh)['uri'];
fwrite($stupid_workaround_fileh,"{json}");
$ch=curl_init();
curl_setopt_array($ch, array(
CURLOPT_URL => "http://127.0.0.1:9999/",
CURLOPT_POST => 1,
CURLOPT_POSTFIELDS => array(
'uploadManifest' => new CURLFile($stupid_workaround_filef,
'application/json', '')
)
));
curl_exec($ch);
Expected result:
----------------
POST / HTTP/1.1
Host: 127.0.0.1:9999
Accept: */*
Content-Length: 186
Content-Type: multipart/form-data; boundary=------------------------2e0011350c342f21
--------------------------2e0011350c342f21
Content-Disposition: form-data; name="uploadManifest"
Content-Type: application/json
{json}
--------------------------2e0011350c342f21--
Actual result:
--------------
POST / HTTP/1.1
Host: 127.0.0.1:9999
Accept: */*
Content-Length: 214
Content-Type: multipart/form-data; boundary=------------------------2e0011350c342f21
--------------------------2e0011350c342f21
Content-Disposition: form-data; name="uploadManifest"; filename="/tmp/phpSh32lX"
Content-Type: application/json
{json}
--------------------------2e0011350c342f21--
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=79004&edit=1