Bug #79855 [Opn]: php_curl lost content-length header on 302 redirect
| From: | kaa at g-it dot su | Date: | Tue, 14 Jul 2020 08:09:17 +0000 |
| Subject: | Bug #79855 [Opn]: php_curl lost content-length header on 302 redirect | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-228028@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=79855&edit=1
ID: 79855
User updated by: kaa at g-it dot su
Reported by: kaa at g-it dot su
Summary: php_curl lost content-length header on 302 redirect
Status: Open
Type: Bug
Package: cURL related
Operating System: Ubuntu 18.04.4 LTS
PHP Version: 7.2.24
Block user comment: N
Private report: N
New Comment:
Yes. I've installed PHP 7.4.8 (cli) (built: Jul 13 2020 16:45:47) ( NTS )
Previous Comments:
------------------------------------------------------------------------
[2020-07-14 07:44:06] cmb@php.net
Well, actually we do no longer actively support 7.2. Does any of the actively supported PHP
versions[1] behave this way?
[1] <https://www.php.net/supported-versions.php>
------------------------------------------------------------------------
[2020-07-14 07:35:56] kaa at g-it dot su
I will illustrate, with your permission)
Me --> Server : POST request with php_curl, content-length is ok
Me <-- Server : 302 Redirect temporary
Me --> Server : GET request with php_curl, content-length is missing
Me <-- Server : 411 Length Required
So I expect that php_curl will add "content-length" parameter on step 3.
------------------------------------------------------------------------
[2020-07-14 07:26:05] sjon@php.net
can you clarify what you think the bug is? The ignored Content-Length on the 302 response is
perfectly valid, and I've tested with CURLOPT_HEADER=true and it correctly includes the
Content-Length header in both the 302 and the final response
------------------------------------------------------------------------
[2020-07-14 07:00:02] kaa at g-it dot su
Description:
------------
Right version of php I'm using is 7.2.24. Installed from Ubuntu repos. PHP_curl with enabled
CURLOPT_FOLLOWLOCATION lost http header "Content-Length" on second redirect with 302
"Redirect temporary".
Seems to be relevant to #53556
Test script:
---------------
$verbose = fopen('curl.log', 'w+');
$ch = curl_init();
curl_setopt($ch, CURLOPT_URL, $path);
curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1);
curl_setopt($ch, CURLOPT_HTTPHEADER, Array (
"Content-Type: application/x-www-form-urlencoded",
"Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8"
));
curl_setopt($ch, CURLOPT_CUSTOMREQUEST, $curl_method);
curl_setopt($ch, CURLOPT_POSTFIELDS, $order_data);
curl_setopt($ch, CURLOPT_FOLLOWLOCATION, true);
curl_setopt($ch, CURLOPT_VERBOSE, true);
curl_setopt($ch, CURLOPT_STDERR, $verbose);
$response = curl_exec($ch);
curl_close($ch);
Actual result:
--------------
* Trying xxx.xxx.xxx.xxx...
* TCP_NODELAY set
* Connected to api.dev.example.com (188.186.236.44) port 443 (#0)
* ALPN, offering http/1.1
* successfully set certificate verify locations:
* CAfile: /etc/ssl/certs/ca-certificates.crt
CApath: /etc/ssl/certs
* SSL connection using TLSv1.2 / ECDHE-RSA-AES256-GCM-SHA384
* ALPN, server accepted to use http/1.1
* Server certificate:
* subject: OU=Domain Control Validated; OU=PositiveSSL Wildcard; CN=*.dev.example.com
* start date: Apr 27 00:00:00 2019 GMT
* expire date: Apr 26 23:59:59 2021 GMT
* subjectAltName: host "api.dev.example.com" matched cert's
"*.dev.example.com"
* issuer: C=GB; ST=Greater Manchester; L=Salford; O=Sectigo Limited; CN=Sectigo RSA Domain
Validation Secure Server CA
* SSL certificate verify ok.
> POST /p2p/v2/payer HTTP/1.1
Host: api.dev.example.com
Content-Type: application/x-www-form-urlencoded
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8
Content-Length: 224
* upload completely sent off: 224 out of 224 bytes
< HTTP/1.1 302 Found
< Server: nginx
< Date: Mon, 13 Jul 2020 14:22:54 GMT
< Content-Type: text/html; charset=utf-8
< Content-Length: 213
< Connection: keep-alive
< Keep-Alive: timeout=20
< Cache-Control: private
< Location:
/api/payer/auth?sessionToken=e744a95992fa405ba10662bbc6908d6bedd48a73cc0d45d589f4ef2f7d7a0b88
< Set-Cookie: returnUrl=http://example.com/returnurl.php; path=/
<
* Ignoring the response-body
* Connection #0 to host api.dev.walletone.com left intact
* Issue another request to this URL: 'https://api.dev.example.com/auth?sessionToken=e744b95992fa405ba10662bbc6908d6b7dd48a73cc0d45d589f4ef2f7d7a0b88'
* Switch from POST to GET
* Found bundle for host api.dev.example.com: 0x5649fd243480 [can pipeline]
* Re-using existing connection! (#0) with host api.dev.example.com
* Connected to api.dev.example.com (188.186.236.44) port 443 (#0)
> POST /auth?sessionToken=e744b95992fa405ba10662bbc6908d6b7dd48a73cc0d45d589f4ef2f7d7a0b88
> HTTP/1.1
Host: api.dev.example.com
Content-Type: application/x-www-form-urlencoded
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8
< HTTP/1.1 411 Length Required
< Server: nginx
< Date: Mon, 13 Jul 2020 14:22:54 GMT
< Content-Type: text/html; charset=us-ascii
< Content-Length: 344
< Connection: keep-alive
< Keep-Alive: timeout=20
<
* Connection #0 to host api.dev.example.com left intact
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=79855&edit=1