Req #81670 [Com]: Access log contains wrong values for "%r" (request URI) format string

From: Date: Wed, 23 Nov 2022 04:51:34 +0000
Subject: Req #81670 [Com]: Access log contains wrong values for "%r" (request URI) format string
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-242877@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=81670&edit=1 ID: 81670 Comment by: ami262 at gmail dot com Reported by: amenshchikov at gmail dot com Summary: Access log contains wrong values for "%r" (request URI) format string Status: Assigned Type: Feature/Change Request Package: FPM related Operating System: Debian 11 PHP Version: 8.1.0 Assigned To: bukka Block user comment: N Private report: N New Comment: if you're actually running into this limit, you are probably abusing GET to begin with. You should use POST to transmit this sort of data -- especially since you even concede that you're using it to update values. If you check the link above, you'll notice that Apache even says "Under normal conditions, the value should not be changed from the default." www.jcpenneykiosk.review Previous Comments: ------------------------------------------------------------------------ [2021-12-01 06:58:45] amenshchikov at gmail dot com Another one place where the same problem takes place — status page. There "request URI" also shows the SCRIPT_NAME (with query string) instead of REQUEST_URI (see https://bugs.php.net/bug.php?id=72319). ------------------------------------------------------------------------ [2021-11-29 22:17:02] amenshchikov at gmail dot com "%{PATH_INFO}e" produces empty string, "%{ORIG_PATH_INFO}e" produces "-". I have the following nginx configuration: server { ... location / { try_files $uri /index.php$is_args$args; } location ~ ^/index\.php(/|$) { fastcgi_pass unix:/run/php/php8.1-fpm.sock; fastcgi_split_path_info ^(.+\.php)(/.*)$; include fastcgi.conf; internal; } ... } ------------------------------------------------------------------------ [2021-11-29 20:53:39] bukka@php.net What I meant that we should update documentation to state that "%r" is for SCRIPT_NAME rather than for REQUEST_URI fcgi env. We cannot just change the value as it could potentially break some scripts that already depend on it being a SCRIPT_NAME. The thing is that internally script name is taken as request uri so I don't think REQUEST_URI is used for anything but might have missed something. In your case it doesn't really matter that much because if we just changed it to REQUEST_URI than it would contain a query so I guess it wouldn't help you. I guess specific flag for path info might help as it might not be always reliable to get it from env (at least the logic around that doesn't seem that straight forward as there are some hacks around Apache). You might actually give it a try and see if "%{PATH_INFO}e" or "%{ORIG_PATH_INFO}e" works for you? ------------------------------------------------------------------------ [2021-11-28 20:06:02] ameshchikov at gmail dot com Yes, you are right. And honestly, I don't think that there is a documentation issue. As I can see, access.format has dedicated placeholder "%f" for script_filename and it seems strange to use "%r" just for script_name (without full path to that script). It seems like "%r" intended to contain certainly request URI (or path info). ------------------------------------------------------------------------ [2021-11-28 19:52:07] bukka@php.net I assume that you really want to be able to log path info, right? ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=81670 -- Edit this bug report at https://bugs.php.net/bug.php?id=81670&edit=1

« previous php.bugs (#242877) next »