Bug #49184 [Com]: INPUT_SERVER returns NULL for set variables (CLI)

From: Date: Thu, 07 May 2020 19:01:38 +0000
Subject: Bug #49184 [Com]: INPUT_SERVER returns NULL for set variables (CLI)
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-226953@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=49184&edit=1

 ID:                 49184
 Comment by:         alexinbeijing at gmail dot com
 Reported by:        m dot kurzyna at crystalpoint dot pl
 Summary:            INPUT_SERVER returns NULL for set variables (CLI)
 Status:             Verified
 Type:               Bug
 Package:            Filter related
 Operating System:   *
 PHP Version:        5.*, 6 (2009-08-07)
 Block user comment: N
 Private report:     N

 New Comment:

Is this as simple as I think it is...?

filter_input() can pull variables from several different "groups", which you can choose
using INPUT_GET, INPUT_POST, INPUT_SERVER, INPUT_ENV, and so on.

Looking at the source code for the PHP interpreter, it looks like environment variables are not
accessed with INPUT_SERVER but rather INPUT_ENV. Actually, if you run the repro code using
INPUT_ENV, it works.

Probably people assumed that the variables in $_SERVER should be accessible using INPUT_SERVER. It
seems that's not the case.

The documentation seems to be faulty, in that it doesn't explain what variables can actually be
accessed through INPUT_SERVER. I can see some of them in the source code for the interpreter, like
"PHP_AUTH_USER", "PHP_AUTH_PW", "PHP_AUTH_DIGEST",
"REQUEST_TIME_FLOAT", "REQUEST_TIME", and so on. You can also get
"SCRIPT_NAME", "SCRIPT_FILENAME", "DOCUMENT_ROOT", etc.

Looking in Google, the Internet seems to be half covered with erroneous statements  that
filter_input(INPUT_SERVER, ...) doesn't work. I wonder why nobody ever stepped in to explain?

If I'm off base, please straighten me out!


Previous Comments:
------------------------------------------------------------------------
[2018-12-11 20:48:57] zoon01 at xigmanas dot com

Also this is a problem with the 7.3.0 release.

------------------------------------------------------------------------
[2018-01-12 19:43:34] m dot patrushev at pitanik dot de

still a problem in 2018 on Versions:
5.6.30
7.1.10

------------------------------------------------------------------------
[2017-01-23 07:44:48] dclarke at blastwave dot org

Still a valid bug in 5.6.30 :

bash-4.3$ ./php-5.6.30_SunOS5.10_sparcv9.001/sapi/cli/php --version
PHP 5.6.30 (cli) (built: Jan 23 2017 01:16:31) 
Copyright (c) 1997-2016 The PHP Group
Zend Engine v2.6.0, Copyright (c) 1998-2016 Zend Technologies
bash-4.3$  cat  foo_var_dump.php 
<?php

var_dump(
          filter_input(INPUT_SERVER,'SOME_ENV_NAME',
                       FILTER_SANITIZE_STRING),
                       $_SERVER['SOME_ENV_NAME'] );

?>
bash-4.3$ SOME_ENV_NAME=this_stuff ./php-5.6.30_SunOS5.10_sparcv9.001/sapi/cli/php foo_var_dump.php 
NULL
string(10) "this_stuff"

It may be worth running a trace through the calls and I did build 
with full debug sysmbols so this is possible. At least on Solaris.

------------------------------------------------------------------------
[2014-10-28 14:40:38] cb at lathspell dot de

If you don't care about fixing this bugs for *years*, please be at least so kind to document
that it is "not intended" to be used from CLI.

------------------------------------------------------------------------
[2014-02-05 12:55:52] jpswade at gmail dot com

It seems this bug still appears in PHP v5.4.24 and has done for over 6 years:

* http://www.php.net/manual/en/function.filter-input.php#77307

The general advice is "do not access superglobal $_server array directly" and the solution
is to use the filter_input() function instead.

* http://stackoverflow.com/questions/19767894/warning-do-not-access-superglobal-post-array-directly-on-netbeans-7-4-for-ph

However, this is a show stopper as you can't fully follow this through because all of the
INPUT_SERVER variables return NULL.

Is PHP serious about not accessing superglobals directly or is this incorrect advice?

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=49184


--
Edit this bug report at https://bugs.php.net/bug.php?id=49184&edit=1


Thread (10 messages)

« previous php.bugs (#226953) next »