Edit report at https://bugs.php.net/bug.php?id=50210&edit=1
ID: 50210
Updated by: php-bugs@lists.php.net
Reported by: tyler dot thackray at gmail dot com
Summary: apache: PHP won't parse multipart/form-data if it was
originally chunk encoded.
-Status: Feedback
+Status: No Feedback
Type: Feature/Change Request
Package: Apache2 related
Operating System: Unix (probably all)
PHP Version: 5.2.11
Assigned To: cmb
Private report: N
New Comment:
No feedback was provided. The bug is being suspended because
we assume that you are no longer experiencing the problem.
If this is not the case and you are able to provide the
information that was requested earlier, please do so and
change the status of the bug back to "Re-Opened". Thank you.
Previous Comments:
------------------------------------------------------------------------
[2021-10-13 15:58:26] cmb@php.net
> // when 'true' multipart data is NOT parsed, but is present at php://stdio
> // when 'false' multipart is parsed into $_FILES and $_POST
I cannot reproduce this; for me, $_FILES and $_POST are populated
either way. Maybe this issue has been fixed in the meantime, or
can anybody still reproduce this with any of the actively
supported PHP versions[1]?
[1] <https://www.php.net/supported-versions.php>
------------------------------------------------------------------------
[2020-12-23 22:16:05] shustrov dot r at gmail dot com
I am using apache2 with mod_php.
Sender script:
<?php
$response = [
"POST /api/responses HTTP/1.1",
"Host: 1vsig-test01.dev.aorti.tech:8080",
"Authorization: Explicit kraken@domain.ru",
"Accept: */*",
"Accept-Encoding: gzip, deflate",
"User-Agent: Python/3.5 aiohttp/3.6.2",
"Content-Type: multipart/form-data; boundary=48d383065e754030ae01de21a3269bd5",
"Transfer-Encoding: chunked",
"",
"24",
"--48d383065e754030ae01de21a3269bd5",
"",
"62",
"Content-Type: application/json",
"Content-Length: 2",
"Content-Disposition: form-data; name=\"meta\"",
"",
"",
"2",
"{}",
"2",
"",
"",
"26",
"--48d383065e754030ae01de21a3269bd5--",
"",
"0",
""
];
$fp = stream_socket_client("tcp://1vsig-test01.dev.aorti.tech:8080", $errno, $errstr, 30);
if (!$fp) {
echo "$errstr ($errno)<br />\n";
} else {
foreach($response as $responseLine){
fwrite($fp, $responseLine."\r\n");
}
while (!feof($fp)) {
echo fgets($fp, 1024);
}
fclose($fp);
}
If I use the "Content-Type: multipart/form-data;
boundary=48d383065e754030ae01de21a3269bd5" header, I completely lose the request body.
$input = file_get_contents('php://input');
$stdin = file_get_contents('php://stdin');
$input and $stdin - empty
If I remove "boundary=48d383065e754030ae01de21a3269bd5" and I have a "Content-Type:
multipart/form-data".
then the request body exists, although not in a structured form
------------------------------------------------------------------------
[2010-03-11 05:57:06] evert at rooftopsolutions dot nl
I believe I might have ran across the same problem (logged as #51191).
In my case the problem is specific to using the FastCGI sapi. It doesn't occur using mod_php.
------------------------------------------------------------------------
[2009-12-09 22:39:24] tyler dot thackray at gmail dot com
I haven't gotten any feedback regarding this issue in some time. Sorry, that code is the most
compact I can make it while still showing the issue. Please let me know if you need anything else to
evaluate this bug.
------------------------------------------------------------------------
[2009-11-18 20:27:05] tyler dot thackray at gmail dot com
Here is the test code, please excuse its length but this is not a simple scenario. The test involves
two scripts "sender.php" and "receiver.php".
RECEIVER.PHP:
<?php
$input = file_get_contents('php://input');
$stdin = file_get_contents('php://stdin');
print "FILES: ";
print_r($_FILES);
print("<br>POST: ");
print_r($_POST);
print("<br>input: ".$input);
print("<br>stdin: ".$stdin);
?>
SENDER.PHP
<?php
// when 'true' multipart data is NOT parsed, but is present at php://stdio
// when 'false' multipart is parsed into $_FILES and $_POST
$chunked = false;
$body1 =
"--AaB03x\r\n".
"Content-Disposition: form-data; name=\"forPOST\"\r\n".
"\r\n".
"1257880790\r\n".
"--AaB03x\r\n";
$body2 =
"Content-Disposition: form-data; name=\"test_file\";
filename=\"test.file\"\r\n".
"Content-Type: application/octet-stream\r\n".
"\r\n".
"binary data\r\n".
"--AaB03x--";
// change the POST to the location of your "receiver.php"
$header =
"POST /test/receiver.php HTTP/1.1\r\n".
"Connection: close\r\n".
"Host: ".$_SERVER['HTTP_HOST']."\r\n".
"Content-Type: multipart/form-data, boundary=AaB03x\r\n";
if ($chunked){
$body = dechex(strlen($body1))."\r\n".$body1."\r\n".
dechex(strlen($body2))."\r\n".$body2."\r\n0\r\n\r\n";
$header .= "Transfer-Encoding: chunked\r\n";
}
else{
$body = $body1 . $body2;
$header .= "Content-Length: ".strlen($body)."\r\n";
}
$header .= "\r\n";
$final = $header . $body;
print "<pre>".$final."<br><br>";
$fp = fsockopen($_SERVER['HTTP_HOST'], 80, $errno, $errstr, 30);
if (!$fp) {
echo "$errstr ($errno)<br />\n";
}
else {
fwrite($fp, $final);
while (!feof($fp)) {
print fgets($fp, 128);
}
fclose($fp);
}
print "</pre>";
?>
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=50210
--
Edit this bug report at https://bugs.php.net/bug.php?id=50210&edit=1