Bug #78929 [PATCH]: plus signs in cookie values are converted to spaces

From: Date: Wed, 03 Jun 2020 23:51:14 +0000
Subject: Bug #78929 [PATCH]: plus signs in cookie values are converted to spaces
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-227307@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=78929&edit=1 ID: 78929 Patch added by: jaroslavas.karmazinas@outlook.com Reported by: kachalin dot alexey at gmail dot com Summary: plus signs in cookie values are converted to spaces Status: Closed Type: Bug Package: URL related Operating System: Irrelevant PHP Version: Irrelevant Assigned To: cmb Block user comment: N Private report: N New Comment: The following pull request has been associated: Patch Name: protect master branches except for the pecl repos against force pushes On GitHub: https://github.com/php/karma/pull/4 Patch: https://github.com/php/karma/pull/4.patch Previous Comments: ------------------------------------------------------------------------ [2020-01-28 14:30:57] cmb@php.net Steve, see bug #79174. ------------------------------------------------------------------------ [2020-01-28 14:23:07] steve at vtsv dot ca While this change fixes the case when using setrawcookie() with data containing a plus sign, it breaks the case when using setcookie() with data containing a space, as setcookie() will url encode the data, turning the space into a plus. The plus no longer gets converted back to a space, and so any validation will fail. ------------------------------------------------------------------------ [2019-12-12 13:23:31] cmb@php.net Automatic comment on behalf of kachalin.alexey@gmail.com Revision: http://git.php.net/?p=php-src.git;a=commit;h=79376ab209f61be03bbf8c1b6177c18261767da8 Log: Fix #78929: plus signs in cookie values are converted to spaces ------------------------------------------------------------------------ [2019-12-12 13:13:20] cmb@php.net You're reasoning makes sense, so I agree that the bugfix should target PHP 7.4 ------------------------------------------------------------------------ [2019-12-10 14:06:04] kachalin dot alexey at gmail dot com While making a good decision, please consider: 1. It's affected only for cookie set by setrawcookie() with "plus sign" inside value. The setcookie() properly encodes a "plus sign". 2. If cookie is set by external system, it's pretty hard to figure out that interaction is failed because of cookie parsing. For example: Cookie WXYZ[]^+_'abcde looks same as WXYZ[]^ _`abcde 3. PHP 7.4 released 3 weeks ago. Most probably it will have long live for several years. Some developers can write software that already need a "plus sign" fix. ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=78929 -- Edit this bug report at https://bugs.php.net/bug.php?id=78929&edit=1

« previous php.bugs (#227307) next »