Bug #67792 [Opn->Ver]: HTTP Authorization schema names are treated as case-sensitive
Edit report at https://bugs.php.net/bug.php?id=67792&edit=1
ID: 67792
Updated by: cmb@php.net
Reported by: bcundal at cundal dot net
Summary: HTTP Authorization schema names are treated as
case-sensitive
-Status: Open
+Status: Verified
Type: Bug
Package: HTTP related
PHP Version: 5.6Git-2014-08-05 (Git)
-Assigned To:
+Assigned To: cmb
Block user comment: N
Private report: N
New Comment:
While RFC 2617 is obsoleted, RFC 7617 explicitly mentions that
"both scheme and parameter names are matched
case-insensitively"[1]. RFC 7616[2] doesn't explicitly specificy
this, but Appendix A descibes the changes from RFC 2617, and
doesn't mention case-(in)sensitivity, so we can assume that
"Digest" also has to be treated case-insensitive.
[1] <https://tools.ietf.org/html/rfc7617#section-2>
[2] <https://tools.ietf.org/html/rfc7616>
Previous Comments:
------------------------------------------------------------------------
[2014-08-05 18:50:52] bcundal at cundal dot net
Description:
------------
php_handle_auth_data treats the Authorization scheme (i.e. "Basic" or "Digest")
as case-sensitive, but RFC 2617 section 1.2 describes this token as case-insensitive.
All instances of strncmp in php_handle_auth_data should be replaced with strnicmp.
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=67792&edit=1
Thread (4 messages)