Bug #78844 [Opn->Nab]: FPM does not support multiple HTTP request headers with the same name
Edit report at https://bugs.php.net/bug.php?id=78844&edit=1
ID: 78844
Updated by: bukka@php.net
Reported by: mikk150 at gmail dot com
Summary: FPM does not support multiple HTTP request headers
with the same name
-Status: Open
+Status: Not a bug
Type: Bug
Package: FPM related
Operating System: Linux
PHP Version: 7.3.11
-Assigned To:
+Assigned To: bukka
Block user comment: N
Private report: N
New Comment:
This is actually a server issue as it should convert it to the comma separated list as CGI spec does
not allow multiple headers with the same name. This is actually what was fixed in nginx relatively
recently: https://hg.nginx.org/nginx/rev/f8f6b9fee66a
Previous Comments:
------------------------------------------------------------------------
[2019-11-20 20:06:46] mikk150 at gmail dot com
Ah, I can see that now, I actually understood https://tools.ietf.org/html/rfc7239#section-4
incorrectly.
I undestood that
GET / HTTP/1.1
Forwarded:for=10.0.0.1;host=php.net;proto=https
Forwarded:for=20.30.40.50;host=awesome.proxy.com;proto=http
Forwarded:for=10.30.20.10;host=second.awesome.proxy.com;proto=http
would become
GET / HTTP/1.1
Forwarded:for=10.0.0.1,for=20.30.40.50,for=10.30.20.10;host=php.net,host=awesome.proxy.com,host=second.awesome.proxy.com;proto=https,proto=http,proto=http
but it actually states that each field-value(seperated by semicolon) MUST NOT occur more than once
per field-value
which means Apache is correct
GET / HTTP/1.1
Forwarded:for=10.0.0.1;host=php.net;proto=https,for=20.30.40.50;host=awesome.proxy.com;proto=http,for=10.30.20.10;host=second.awesome.proxy.com;proto=http
As this is actually correct
------------------------------------------------------------------------
[2019-11-20 19:03:45] requinix@php.net
The ability to get headers is highly dependent on the SAPI. Apache's works nicely, but php -s
is just a quick development server that is not going to be suitable for all purposes.
So really, the issue here is that php-fpm doesn't properly handle multiple headers. The HTTP
spec requires that multiple headers only be allowed when their values can be combined into
comma-separated lists, which means $_SERVER and getallheaders() are still sufficient.
------------------------------------------------------------------------
[2019-11-20 18:44:40] mikk150 at gmail dot com
summary more understandable
------------------------------------------------------------------------
[2019-11-20 17:39:23] mikk150 at gmail dot com
Description:
------------
PHP $_SERVER['HTTP_*'] superglobal and getallheaders() does not actually give all headers.
If you have multiple header lines with same name, each SAPI does totally different thing(and all of
them are wrong)
If I make request:
GET / HTTP/1.1
Forwarded: for=10.0.0.1,for=20.30.40.50;host=php.net,host=awesome.proxy.com;proto=https,proto=http
Forwarded: for=10.30.20.10;host=second.awesome.proxy.com;proto=http
I get 3 different responses based on SAPI
FPM only keeps last header
php -s only keeps first header
apache concatenates them with ,
PHP should implement new method to get all headers OR implement some class that has method to get
all headers
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=78844&edit=1
Thread (5 messages)