#35975 [NEW]: session_set_cookie_params and setcookie
| From: | waitman at waitman dot net | Date: | Thu, 12 Jan 2006 00:32:47 +0000 |
| Subject: | #35975 [NEW]: session_set_cookie_params and setcookie | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-91784@lists.php.net to get a copy of this message | ||
From: waitman at waitman dot net
Operating system: Linux
PHP version: 4.4.1
PHP Bug Type: Session related
Bug description: session_set_cookie_params and setcookie
Description:
------------
Both the session_set_cookie_params() and setcookie() functions output
dates in the format:
Wdy, DD Mon YY HH:MM:SS GMT
Which appears to be correctly parsed in browsers such as MSIE and
Mozilla/Firefox. However, I have noticed that some of the popular Mobile
Client Web Browsers (such as OpenWave) do not parse the date properly and
set the "expires" value to the end of the current session, regardless of
the "expires" value intended.
According to RFC 2109, the "expires" value is obsolete and replaced with
"max-age" (which is not set by either function listed above). But it does
state that browser vendors should be aware that the "Expires" tag may be
used as defined by the original Netscape proposal.
The original Netscape proposal states the following about the Expire
value:
"The date string is formatted as:
Wdy, DD-Mon-YYYY HH:MM:SS GMT
This is based on RFC 822, RFC 850, RFC 1036, and RFC 1123, with the
variations that the only legal time zone is GMT and the separators between
the elements of the date must be dashes."
My opinion is that either the PHP functions should use the "Max Age" value
(with an integer indicating number of seconds) per the RFC or the date
format returned should have the dash between the day, month and year.
Reproduce code:
---------------
<?php
$time=mktime(1,1,1,3,9,2008);
setcookie("foo", "bar", $time, "/", ".example.com", 0);
// and
session_set_cookie_params ( 10000, "/", ".nodemap.com", 0);
session_start();
?>
Expected result:
----------------
200 OK
Set-Cookie: foo=bar; expires=Sun, 09-Mar-2008 09:01:01 GMT; path=/;
domain=.example.com
Set-Cookie: PHPSESSID=e5e7ea79f6450d219c7471e559a29bab; expires=Thu,
12-Jan-2006 03:16:47 GMT; path=/; domain=.example.com
Actual result:
--------------
200 OK
Set-Cookie: foo=bar; expires=Sun, 09 Mar 2008 09:01:01 GMT; path=/;
domain=.example.com
Set-Cookie: PHPSESSID=e5e7ea79f6450d219c7471e559a29bab; expires=Thu, 12
Jan 2006 03:16:47 GMT; path=/; domain=.example.com
--
Edit bug report at http://bugs.php.net/?id=35975&edit=1
--
Try a CVS snapshot (PHP 4.4): http://bugs.php.net/fix.php?id=35975&r=trysnapshot44
Try a CVS snapshot (PHP 5.1): http://bugs.php.net/fix.php?id=35975&r=trysnapshot51
Try a CVS snapshot (PHP 6.0): http://bugs.php.net/fix.php?id=35975&r=trysnapshot60
Fixed in CVS: http://bugs.php.net/fix.php?id=35975&r=fixedcvs
Fixed in release: http://bugs.php.net/fix.php?id=35975&r=alreadyfixed
Need backtrace: http://bugs.php.net/fix.php?id=35975&r=needtrace
Need Reproduce Script: http://bugs.php.net/fix.php?id=35975&r=needscript
Try newer version: http://bugs.php.net/fix.php?id=35975&r=oldversion
Not developer issue: http://bugs.php.net/fix.php?id=35975&r=support
Expected behavior: http://bugs.php.net/fix.php?id=35975&r=notwrong
Not enough info: http://bugs.php.net/fix.php?id=35975&r=notenoughinfo
Submitted twice: http://bugs.php.net/fix.php?id=35975&r=submittedtwice
register_globals: http://bugs.php.net/fix.php?id=35975&r=globals
PHP 3 support discontinued: http://bugs.php.net/fix.php?id=35975&r=php3
Daylight Savings: http://bugs.php.net/fix.php?id=35975&r=dst
IIS Stability: http://bugs.php.net/fix.php?id=35975&r=isapi
Install GNU Sed: http://bugs.php.net/fix.php?id=35975&r=gnused
Floating point limitations: http://bugs.php.net/fix.php?id=35975&r=float
No Zend Extensions: http://bugs.php.net/fix.php?id=35975&r=nozend
MySQL Configuration Error: http://bugs.php.net/fix.php?id=35975&r=mysqlcfg