Bug #78844 [Opn->Nab]: FPM does not support multiple HTTP request headers with the same name

From: Date: Thu, 09 Feb 2023 16:31:07 +0000
Subject: Bug #78844 [Opn->Nab]: FPM does not support multiple HTTP request headers with the same name
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-243701@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=78844&edit=1

 ID:                 78844
 Updated by:         bukka@php.net
 Reported by:        mikk150 at gmail dot com
 Summary:            FPM does not support multiple HTTP request headers
                     with the same name
-Status:             Open
+Status:             Not a bug
 Type:               Bug
 Package:            FPM related
 Operating System:   Linux
 PHP Version:        7.3.11
-Assigned To:        
+Assigned To:        bukka
 Block user comment: N
 Private report:     N

 New Comment:

This is actually a server issue as it should convert it to the comma separated list as CGI spec does
not allow multiple headers with the same name. This is actually what was fixed in nginx relatively
recently: https://hg.nginx.org/nginx/rev/f8f6b9fee66a


Previous Comments:
------------------------------------------------------------------------
[2019-11-20 20:06:46] mikk150 at gmail dot com

Ah, I can see that now, I actually understood https://tools.ietf.org/html/rfc7239#section-4
incorrectly.

I undestood that
GET / HTTP/1.1
Forwarded:for=10.0.0.1;host=php.net;proto=https
Forwarded:for=20.30.40.50;host=awesome.proxy.com;proto=http
Forwarded:for=10.30.20.10;host=second.awesome.proxy.com;proto=http

would become
GET / HTTP/1.1
Forwarded:for=10.0.0.1,for=20.30.40.50,for=10.30.20.10;host=php.net,host=awesome.proxy.com,host=second.awesome.proxy.com;proto=https,proto=http,proto=http


but it actually states that each field-value(seperated by semicolon) MUST NOT occur more than once
per field-value

which means Apache is correct
GET / HTTP/1.1
Forwarded:for=10.0.0.1;host=php.net;proto=https,for=20.30.40.50;host=awesome.proxy.com;proto=http,for=10.30.20.10;host=second.awesome.proxy.com;proto=http

As this is actually correct

------------------------------------------------------------------------
[2019-11-20 19:03:45] requinix@php.net

The ability to get headers is highly dependent on the SAPI. Apache's works nicely, but php -s
is just a quick development server that is not going to be suitable for all purposes.

So really, the issue here is that php-fpm doesn't properly handle multiple headers. The HTTP
spec requires that multiple headers only be allowed when their values can be combined into
comma-separated lists, which means $_SERVER and getallheaders() are still sufficient.

------------------------------------------------------------------------
[2019-11-20 18:44:40] mikk150 at gmail dot com

summary more understandable

------------------------------------------------------------------------
[2019-11-20 17:39:23] mikk150 at gmail dot com

Description:
------------
PHP $_SERVER['HTTP_*'] superglobal and getallheaders() does not actually give all headers.
If you have multiple header lines with same name, each SAPI does totally different thing(and all of
them are wrong)

If I make request:
GET / HTTP/1.1
Forwarded: for=10.0.0.1,for=20.30.40.50;host=php.net,host=awesome.proxy.com;proto=https,proto=http
Forwarded: for=10.30.20.10;host=second.awesome.proxy.com;proto=http

I get 3 different responses based on SAPI

FPM only keeps last header
php -s only keeps first header
apache concatenates them with ,

PHP should implement new method to get all headers OR implement some class that has method to get
all headers



------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=78844&edit=1


Thread (5 messages)

« previous php.bugs (#243701) next »