Bug #81305 [Ver->Csd]: Development Webserver Drops Requests With "Upgrade" Header
Edit report at https://bugs.php.net/bug.php?id=81305&edit=1
ID: 81305
Updated by: git@php.net
Reported by: parsonswy at gmail dot com
Summary: Development Webserver Drops Requests With "Upgrade"
Header
-Status: Verified
+Status: Closed
Type: Bug
Package: Built-in web server
Operating System: Windows
PHP Version: 7.4
Assigned To: cmb
Block user comment: N
Private report: N
New Comment:
Automatic comment on behalf of cmb69
Revision: https://github.com/php/php-src/commit/d1ccb5bd0c7f6ed981e1d0bbfc42fbf5c7561b2c
Log: Fix #81305: Built-in Webserver Drops Requests With "Upgrade" Header
Previous Comments:
------------------------------------------------------------------------
[2021-07-29 10:21:27] cmb@php.net
The following pull request has been associated:
Patch Name: Fix #81305: Built-in Webserver Drops Requests With "Upgrade" Header
On GitHub: https://github.com/php/php-src/pull/7316
Patch: https://github.com/php/php-src/pull/7316.patch
------------------------------------------------------------------------
[2021-07-28 13:58:11] cmb@php.net
Fun fact: while our HTTP parser has support for upgrade, this
isn't supported by our Webserver code.
------------------------------------------------------------------------
[2021-07-28 03:37:35] parsonswy at gmail dot com
Description:
------------
The development server appears to discard any HTTP requests that have the "Upgrade" header
as malformed. I couldn't find information on what HTTP spec the server is built to support, if
any. Actually implementing the HTTP upgrade protocol seems overkill for the scope of the server.
Having it at least accept the request and ignore the upgrade offer I think is still spec compliant
and preferable to generic discard and socket close. Alternatively, responding with HTTP/BAD_REQUEST
and documenting the behavior is a more transparent option.
I have confirmed that my client was indicating HTTP/1.1 so the 'Upgrade' header should
still be legal on the request. I don't actually need to use HTTP/2, I had a Java client that I
was testing which requested an upgrade by default and this was a difficult issue to debug.
Tested on PHP/8.0.3 (Native Windows & alpine docker), PHP/8.0.8 alpine docker.
Test script:
---------------
Succeeds: curl "http://localhost:8081"
--trace-ascii - -X GET
Fails "Invalid request (Malformed HTTP request)": curl "http://localhost:8081" --trace-ascii - -X GET -H
"Upgrade: HTTP/2.0" -H "Connection: upgrade"
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=81305&edit=1
Thread (4 messages)