Req #81646 [Com]: header() can violate HTTP RFC
| From: | marlynrasavong at gmail dot com | Date: | Thu, 29 Dec 2022 08:34:39 +0000 |
| Subject: | Req #81646 [Com]: header() can violate HTTP RFC | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-243271@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=81646&edit=1
ID: 81646
Comment by: marlynrasavong at gmail dot com
Reported by: ive_jihwan at kaist dot ac dot kr
Summary: header() can violate HTTP RFC
Status: Open
Type: Feature/Change Request
Package: *Network Functions
Operating System: any
PHP Version: 8.0.13
Block user comment: N
Private report: N
New Comment:
Did you have got any result for this bug ? (https://www.benefitscal.ltd/)github.com
Previous Comments:
------------------------------------------------------------------------
[2022-12-20 09:02:54] robertsonlpj11 at gmail dot com
This article is truly astounding. Appreciative for sharing. A commitment of appreciation is all
together for the association, keep on sharing such an information.
(https://www.mysainsburys.net/)github.com
------------------------------------------------------------------------
[2021-11-21 06:45:54] ive_jihwan at kaist dot ac dot kr
Description:
------------
RFC7230, which is released in June 2014, explicitly specifies HTTP-version field as starting with
"HTTP" case-sensitively.
https://datatracker.ietf.org/doc/html/rfc7230#section-2.6
However, PHP's header() function compares first 5 bytes with "HTTP/" case
insensitively, and copies whole input line to output message line. This let clients misunderstand
HTTP version.
https://github.com/php/php-src/blob/master/main/SAPI.c#L755
It can be patched by fixing starting 4 bytes as uppercase "HTTP" or change strncasecmp to
strncmp which drops a support standards before RFC7230.
Test script:
---------------
<?php
header("http/1.1 200 OK");
Expected result:
----------------
Either of followings.
- header() throws an warning/error that notices HTTP/1.1 or higher must use uppercase
"HTTP"
- Internally convert to uppercase HTTP
Actual result:
--------------
(Raw HTTP response message)
http/1.1 200 OK
Date: Sun, 21 Nov 2021 06:38:10 GMT
Connection: close
X-Powered-By: PHP/8.0.13
Content-type: text/html; charset=UTF-8
(curl in verbose, downgraded HTTP1.0)
> GET /http11.php HTTP/1.1
> Host: localhost:1234
> User-Agent: curl/7.68.0
> Accept: */*
>
* HTTP 1.0, assume close after body
< http/1.1 200 OK
< Host: localhost:1234
< Date: Sun, 21 Nov 2021 06:35:19 GMT
< Connection: close
< X-Powered-By: PHP/8.0.13
< Content-type: text/html; charset=UTF-8
(Chrome)
Translate it as HTTP/1.1
(Safari)
Translate it as HTTP/1.1
(Firefox)
Fail to translate it as valid HTTP
For browser screenshots, here is a link: https://imgur.com/a/PtrmfTA
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=81646&edit=1