Bug #81305 [Ver->Csd]: Development Webserver Drops Requests With "Upgrade" Header

From: Date: Thu, 29 Jul 2021 11:23:01 +0000
Subject: Bug #81305 [Ver->Csd]: Development Webserver Drops Requests With "Upgrade" Header
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-235453@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=81305&edit=1

 ID:                 81305
 Updated by:         git@php.net
 Reported by:        parsonswy at gmail dot com
 Summary:            Development Webserver Drops Requests With "Upgrade"
                     Header
-Status:             Verified
+Status:             Closed
 Type:               Bug
 Package:            Built-in web server
 Operating System:   Windows
 PHP Version:        7.4
 Assigned To:        cmb
 Block user comment: N
 Private report:     N

 New Comment:

Automatic comment on behalf of cmb69
Revision: https://github.com/php/php-src/commit/d1ccb5bd0c7f6ed981e1d0bbfc42fbf5c7561b2c
Log: Fix #81305: Built-in Webserver Drops Requests With "Upgrade" Header


Previous Comments:
------------------------------------------------------------------------
[2021-07-29 10:21:27] cmb@php.net

The following pull request has been associated:

Patch Name: Fix #81305: Built-in Webserver Drops Requests With "Upgrade" Header
On GitHub:  https://github.com/php/php-src/pull/7316
Patch:      https://github.com/php/php-src/pull/7316.patch

------------------------------------------------------------------------
[2021-07-28 13:58:11] cmb@php.net

Fun fact: while our HTTP parser has support for upgrade, this
isn't supported by our Webserver code.

------------------------------------------------------------------------
[2021-07-28 03:37:35] parsonswy at gmail dot com

Description:
------------
The development server appears to discard any HTTP requests that have the "Upgrade" header
as malformed. I couldn't find information on what HTTP spec the server is built to support, if
any. Actually implementing the HTTP upgrade protocol seems overkill for the scope of the server.
Having it at least accept the request and ignore the upgrade offer I think is still spec compliant
and preferable to generic discard and socket close. Alternatively, responding with HTTP/BAD_REQUEST
and documenting the behavior is a more transparent option.

I have confirmed that my client was indicating HTTP/1.1 so the 'Upgrade' header should
still be legal on the request. I don't actually need to use HTTP/2, I had a Java client that I
was testing which requested an upgrade by default and this was a difficult issue to debug.

Tested on PHP/8.0.3 (Native Windows & alpine docker), PHP/8.0.8 alpine docker.

Test script:
---------------
Succeeds: curl "http://localhost:8081"
--trace-ascii - -X GET

Fails "Invalid request (Malformed HTTP request)": curl "http://localhost:8081" --trace-ascii - -X GET -H
"Upgrade: HTTP/2.0" -H "Connection: upgrade"



------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=81305&edit=1


Thread (4 messages)

« previous php.bugs (#235453) next »