Edit report at https://bugs.php.net/bug.php?id=49184&edit=1
ID: 49184
Comment by: alexinbeijing at gmail dot com
Reported by: m dot kurzyna at crystalpoint dot pl
Summary: INPUT_SERVER returns NULL for set variables (CLI)
Status: Verified
Type: Bug
Package: Filter related
Operating System: *
PHP Version: 5.*, 6 (2009-08-07)
Block user comment: N
Private report: N
New Comment:
Is this as simple as I think it is...?
filter_input() can pull variables from several different "groups", which you can choose
using INPUT_GET, INPUT_POST, INPUT_SERVER, INPUT_ENV, and so on.
Looking at the source code for the PHP interpreter, it looks like environment variables are not
accessed with INPUT_SERVER but rather INPUT_ENV. Actually, if you run the repro code using
INPUT_ENV, it works.
Probably people assumed that the variables in $_SERVER should be accessible using INPUT_SERVER. It
seems that's not the case.
The documentation seems to be faulty, in that it doesn't explain what variables can actually be
accessed through INPUT_SERVER. I can see some of them in the source code for the interpreter, like
"PHP_AUTH_USER", "PHP_AUTH_PW", "PHP_AUTH_DIGEST",
"REQUEST_TIME_FLOAT", "REQUEST_TIME", and so on. You can also get
"SCRIPT_NAME", "SCRIPT_FILENAME", "DOCUMENT_ROOT", etc.
Looking in Google, the Internet seems to be half covered with erroneous statements that
filter_input(INPUT_SERVER, ...) doesn't work. I wonder why nobody ever stepped in to explain?
If I'm off base, please straighten me out!
Previous Comments:
------------------------------------------------------------------------
[2018-12-11 20:48:57] zoon01 at xigmanas dot com
Also this is a problem with the 7.3.0 release.
------------------------------------------------------------------------
[2018-01-12 19:43:34] m dot patrushev at pitanik dot de
still a problem in 2018 on Versions:
5.6.30
7.1.10
------------------------------------------------------------------------
[2017-01-23 07:44:48] dclarke at blastwave dot org
Still a valid bug in 5.6.30 :
bash-4.3$ ./php-5.6.30_SunOS5.10_sparcv9.001/sapi/cli/php --version
PHP 5.6.30 (cli) (built: Jan 23 2017 01:16:31)
Copyright (c) 1997-2016 The PHP Group
Zend Engine v2.6.0, Copyright (c) 1998-2016 Zend Technologies
bash-4.3$ cat foo_var_dump.php
<?php
var_dump(
filter_input(INPUT_SERVER,'SOME_ENV_NAME',
FILTER_SANITIZE_STRING),
$_SERVER['SOME_ENV_NAME'] );
?>
bash-4.3$ SOME_ENV_NAME=this_stuff ./php-5.6.30_SunOS5.10_sparcv9.001/sapi/cli/php foo_var_dump.php
NULL
string(10) "this_stuff"
It may be worth running a trace through the calls and I did build
with full debug sysmbols so this is possible. At least on Solaris.
------------------------------------------------------------------------
[2014-10-28 14:40:38] cb at lathspell dot de
If you don't care about fixing this bugs for *years*, please be at least so kind to document
that it is "not intended" to be used from CLI.
------------------------------------------------------------------------
[2014-02-05 12:55:52] jpswade at gmail dot com
It seems this bug still appears in PHP v5.4.24 and has done for over 6 years:
* http://www.php.net/manual/en/function.filter-input.php#77307
The general advice is "do not access superglobal $_server array directly" and the solution
is to use the filter_input() function instead.
* http://stackoverflow.com/questions/19767894/warning-do-not-access-superglobal-post-array-directly-on-netbeans-7-4-for-ph
However, this is a show stopper as you can't fully follow this through because all of the
INPUT_SERVER variables return NULL.
Is PHP serious about not accessing superglobals directly or is this incorrect advice?
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=49184
--
Edit this bug report at https://bugs.php.net/bug.php?id=49184&edit=1