#23454 [Ver]: Combining GET and POST array values is broken
| From: | rasmus@php.net | Date: | Mon, 05 May 2003 22:53:44 +0000 |
| Subject: | #23454 [Ver]: Combining GET and POST array values is broken | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-39118@lists.php.net to get a copy of this message | ||
ID: 23454
Updated by: rasmus@php.net
Reported By: oregon at pobox dot com
Status: Verified
Bug Type: *General Issues
Operating System: ANY
PHP Version: 4.3.2RC3-dev
New Comment:
You should also mention that before 4.3.0 it was broken the other way.
The $_GET, $_POST and $_COOKIE arrays contained all 3 elements. Right
now the question is which way we want to break it. Do we want to
pollute GPC arrays with data from the other methods (potentially
overwriting data) or do we want to break BC and have it slightly more
correct but still have broken $_REQUEST and $GLOBALS. Ideally we want
it to be right for both, but I don't really see how to do that without
breaking the reference ties between the autoglobals.
Previous Comments:
------------------------------------------------------------------------
[2003-05-05 17:49:35] sniper@php.net
Expected results:
_GET: Array
(
[person] => Array
(
[age] => 27
)
)
_POST: Array
(
[person] => Array
(
[sname] => bar
)
)
_COOKIE: Array
(
[person] => Array
(
[fname] => foo
)
)
_REQUEST: Array
(
[person] => Array
(
[age] => 27
[fname] => foo
[sname] => bar
)
)
person: Array
(
[age] => 27
[fname] => foo
[sname] => bar
)
(the last two are broken since 4.3.0 and only contain
"fname" entry)
------------------------------------------------------------------------
[2003-05-05 17:43:42] sniper@php.net
Here's a bit more extended version of the test script,
including cookies too:
<?php setcookie("person[fname]", "foobar"); ?>
<form action="bug23454.php?person[age]=27" method=post>
<input type=text size=32 name="person[sname]">
<input type=submit>
</form>
<pre>
<?php
echo phpversion();
echo '<br>register_globals = ', ini_get('register_globals'),
'<br>';
print "_GET: "; print_r($_GET);
print "_POST: "; print_r($_POST);
print "_COOKIE: "; print_r($_COOKIE);
print "_REQUEST: "; print_r($_REQUEST);
print "person: "; print_r($person);
?>
</pre>
------------------------------------------------------------------------
[2003-05-02 18:40:57] philip@php.net
This might be related to closed bug #20796:
http://bugs.php.net/20796
Marking this one (#23454) critical as it makes autoglobals unreliable
and register_globals should work too. btw, track_vars doesn't exist
anymore, it's always on.
------------------------------------------------------------------------
[2003-05-02 18:30:13] michael dot mauch at gmx dot de
It's not only with about register_globals=on, the GET data are also
missing from $_REQUEST if register_globals=off.
------------------------------------------------------------------------
[2003-05-02 17:45:49] michael dot mauch at gmx dot de
Complete script:
<form action="bug23454.php?person[age]=27" method=post>
<input type=text size=32 name="person[sname]">
<input type=submit>
</form>
<pre>
<?php
print "_REQUEST: "; print_r($_REQUEST);
print "_GET: "; print_r($_GET);
print "_POST: "; print_r($_POST);
print "person: "; print_r($person);
?>
</pre>
In 4.2.3 with register_globals on, I get both the POST and GET data
in $_REQUEST, $person, $_GET (wrong), $_POST (wrong).
In 4.2.3 with register_globals off, I get the POST data
in $_REQUEST and $_POST, the GET data only in $_GET (not in
$_REQUEST).
In php4-STABLE-200305011130 with register_globals on, I see the POST
data in $_REQUEST, $_POST and $person, but the GET data is only in
$_GET (not in $_REQUEST and not in $person).
In php4-STABLE-200305011130 with register_globals off, it's the same as
with 4.2.3 - i.e. the GET data is missing from $_REQUEST.
To me, this does indeed look like a bug.
I also checked with non-array variables: fortunately they do work
like advertized.
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
http://bugs.php.net/23454
--
Edit this bug report at http://bugs.php.net/?id=23454&edit=1