Bug #67792 [Ver->Csd]: HTTP Authorization schema names are treated as case-sensitive
Edit report at https://bugs.php.net/bug.php?id=67792&edit=1
ID: 67792
Updated by: cmb@php.net
Reported by: bcundal at cundal dot net
Summary: HTTP Authorization schema names are treated as
case-sensitive
-Status: Verified
+Status: Closed
Type: Bug
Package: HTTP related
PHP Version: 5.6Git-2014-08-05 (Git)
Assigned To: cmb
Block user comment: N
Private report: N
New Comment:
Fixed: <https://github.com/php/php-src/commit/39ddf6b89cc5013f6e1ded90a238cd8b610e6597>
Previous Comments:
------------------------------------------------------------------------
[2021-04-22 16:27:03] cmb@php.net
The following pull request has been associated:
Patch Name: Fix #67792: HTTP Authorization schemes are treated as case-sensitive
On GitHub: https://github.com/php/php-src/pull/6900
Patch: https://github.com/php/php-src/pull/6900.patch
------------------------------------------------------------------------
[2021-04-22 16:14:22] cmb@php.net
While RFC 2617 is obsoleted, RFC 7617 explicitly mentions that
"both scheme and parameter names are matched
case-insensitively"[1]. RFC 7616[2] doesn't explicitly specificy
this, but Appendix A descibes the changes from RFC 2617, and
doesn't mention case-(in)sensitivity, so we can assume that
"Digest" also has to be treated case-insensitive.
[1] <https://tools.ietf.org/html/rfc7617#section-2>
[2] <https://tools.ietf.org/html/rfc7616>
------------------------------------------------------------------------
[2014-08-05 18:50:52] bcundal at cundal dot net
Description:
------------
php_handle_auth_data treats the Authorization scheme (i.e. "Basic" or "Digest")
as case-sensitive, but RFC 2617 section 1.2 describes this token as case-insensitive.
All instances of strncmp in php_handle_auth_data should be replaced with strnicmp.
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=67792&edit=1
Thread (4 messages)