Req #81646 [Com]: header() can violate HTTP RFC

From: Date: Tue, 08 Aug 2023 06:58:18 +0000
Subject: Req #81646 [Com]: header() can violate HTTP RFC
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-245128@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=81646&edit=1 ID: 81646 Comment by: blooketjoinguide at gmail dot com Reported by: ive_jihwan at kaist dot ac dot kr Summary: header() can violate HTTP RFC Status: Open Type: Feature/Change Request Package: *Network Functions Operating System: any PHP Version: 8.0.13 Block user comment: N Private report: N New Comment: Blooket Join Guide will provide you with all the information about Blooket like how to join Blooket, what the Blooket Code is, and how to use it, etc. https://github.com/BlooketStephen Previous Comments: ------------------------------------------------------------------------ [2023-06-09 06:16:36] galiyo5302 at ozatvn dot com So, if you’re a Kroger employee, make sure to log in to feed.kroger.com regularly to stay updated and organized.Do you have any questions about the portal or how to use it? Feel free to leave a comment below and we’ll be happy to help! ------------------------------------------------------------------------ [2023-05-29 07:59:15] phamdinhkhangu315 at gmail dot com The header() function you mentioned appears to be related to PHP, where it is used to send raw HTTP headers. While it is possible to use the header() function in a way that violates the HTTP RFC (Request for Comments), it's important to note that it's not the function itself that violates the RFC, but rather the specific usage or the content of the headers being sent. The HTTP RFC, particularly RFC 7230, defines the syntax and semantics of the HTTP protocol. It specifies how requests and responses should be formatted, including the structure and acceptable values for headers. When using the header() function, it's crucial to ensure that the headers being sent comply with the HTTP RFC. Violations of the RFC can occur if the headers contain incorrect syntax, invalid characters, or inappropriate values. For example, sending a header with a malformed date or a header value that includes prohibited characters could be considered a violation. It's important to follow the HTTP RFC guidelines to ensure proper communication between clients and servers. While the header() function itself doesn't enforce RFC compliance, it's the responsibility of the developer to use it correctly and send headers that adhere to the HTTP specifications. (https://www.mcdvoice.onl/)github.com ------------------------------------------------------------------------ [2022-12-29 08:34:39] marlynrasavong at gmail dot com Did you have got any result for this bug ? (https://www.benefitscal.ltd/)github.com ------------------------------------------------------------------------ [2022-12-20 09:02:54] robertsonlpj11 at gmail dot com This article is truly astounding. Appreciative for sharing. A commitment of appreciation is all together for the association, keep on sharing such an information. (https://www.mysainsburys.net/)github.com ------------------------------------------------------------------------ [2021-11-21 06:45:54] ive_jihwan at kaist dot ac dot kr Description: ------------ RFC7230, which is released in June 2014, explicitly specifies HTTP-version field as starting with "HTTP" case-sensitively. https://datatracker.ietf.org/doc/html/rfc7230#section-2.6 However, PHP's header() function compares first 5 bytes with "HTTP/" case insensitively, and copies whole input line to output message line. This let clients misunderstand HTTP version. https://github.com/php/php-src/blob/master/main/SAPI.c#L755 It can be patched by fixing starting 4 bytes as uppercase "HTTP" or change strncasecmp to strncmp which drops a support standards before RFC7230. Test script: --------------- <?php header("http/1.1 200 OK"); Expected result: ---------------- Either of followings. - header() throws an warning/error that notices HTTP/1.1 or higher must use uppercase "HTTP" - Internally convert to uppercase HTTP Actual result: -------------- (Raw HTTP response message) http/1.1 200 OK Date: Sun, 21 Nov 2021 06:38:10 GMT Connection: close X-Powered-By: PHP/8.0.13 Content-type: text/html; charset=UTF-8 (curl in verbose, downgraded HTTP1.0) > GET /http11.php HTTP/1.1 > Host: localhost:1234 > User-Agent: curl/7.68.0 > Accept: */* > * HTTP 1.0, assume close after body < http/1.1 200 OK < Host: localhost:1234 < Date: Sun, 21 Nov 2021 06:35:19 GMT < Connection: close < X-Powered-By: PHP/8.0.13 < Content-type: text/html; charset=UTF-8 (Chrome) Translate it as HTTP/1.1 (Safari) Translate it as HTTP/1.1 (Firefox) Fail to translate it as valid HTTP For browser screenshots, here is a link: https://imgur.com/a/PtrmfTA ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=81646&edit=1

« previous php.bugs (#245128) next »