Bug #78929 [PATCH]: plus signs in cookie values are converted to spaces
| From: | jaroslavas.karmazinas@outlook.com | Date: | Wed, 03 Jun 2020 23:51:14 +0000 |
| Subject: | Bug #78929 [PATCH]: plus signs in cookie values are converted to spaces | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-227307@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=78929&edit=1
ID: 78929
Patch added by: jaroslavas.karmazinas@outlook.com
Reported by: kachalin dot alexey at gmail dot com
Summary: plus signs in cookie values are converted to spaces
Status: Closed
Type: Bug
Package: URL related
Operating System: Irrelevant
PHP Version: Irrelevant
Assigned To: cmb
Block user comment: N
Private report: N
New Comment:
The following pull request has been associated:
Patch Name: protect master branches except for the pecl repos against force pushes
On GitHub: https://github.com/php/karma/pull/4
Patch: https://github.com/php/karma/pull/4.patch
Previous Comments:
------------------------------------------------------------------------
[2020-01-28 14:30:57] cmb@php.net
Steve, see bug #79174.
------------------------------------------------------------------------
[2020-01-28 14:23:07] steve at vtsv dot ca
While this change fixes the case when using setrawcookie() with data containing a plus sign, it
breaks the case when using setcookie() with data containing a space, as setcookie() will url encode
the data, turning the space into a plus. The plus no longer gets converted back to a space, and so
any validation will fail.
------------------------------------------------------------------------
[2019-12-12 13:23:31] cmb@php.net
Automatic comment on behalf of kachalin.alexey@gmail.com
Revision: http://git.php.net/?p=php-src.git;a=commit;h=79376ab209f61be03bbf8c1b6177c18261767da8
Log: Fix #78929: plus signs in cookie values are converted to spaces
------------------------------------------------------------------------
[2019-12-12 13:13:20] cmb@php.net
You're reasoning makes sense, so I agree that the bugfix should
target PHP 7.4
------------------------------------------------------------------------
[2019-12-10 14:06:04] kachalin dot alexey at gmail dot com
While making a good decision, please consider:
1. It's affected only for cookie set by setrawcookie() with "plus sign" inside value.
The setcookie() properly encodes a "plus sign".
2. If cookie is set by external system, it's pretty hard to figure out that interaction is
failed because of cookie parsing.
For example: Cookie WXYZ[]^+_'abcde looks same as WXYZ[]^ _`abcde
3. PHP 7.4 released 3 weeks ago. Most probably it will have long live for several years. Some
developers can write software that already need a "plus sign" fix.
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=78929
--
Edit this bug report at https://bugs.php.net/bug.php?id=78929&edit=1