PHP 4.0 Bug #5942 Updated: PHP4 either does not parse html/htm files or breaks autorization
| From: | Bug Database | Date: | Fri, 04 Aug 2000 07:14:17 +0000 |
| Subject: | PHP 4.0 Bug #5942 Updated: PHP4 either does not parse html/htm files or breaks autorization | ||
| Groups: | php.dev | ||
| Request: | Send a blank email to php-dev+get-27614@lists.php.net to get a copy of this message | ||
ID: 5942
User Update by: byg@fis.ru
Old-Status: Closed
Status: Feedback
Bug Type: Scripting Engine problem
Description: PHP4 either does not parse html/htm files or breaks autorization
> I am having problems parsing this bug report. Have you registered .html as a PHP mime type?
Yep. As I already told, I had tried all available combination of AddType/AddHandler/mime.types and I
had no luck.
I'd notice that there's proven working httpd.conf, which is working fine with 3.0.16.
(AFAIK the only difference between configs for PHP3 and PHP4 modules is
application/x-httpd-php3->application/x-httpd-php conversion)
I should emphase that the behaviour depends on location of httpd.conf and Document_Root.
It either doesn't parse htm/html files or has problems with authorization.
> And if you are doing Apache-level HTTP authorization, this is done well before PHP gets
> involved in the request process, so I don't understand that part of your bug report either.
> Please try to explain yourself better and re-submit with a single problem per bug report.
>
I consider that there's a PHP4 issue because:
1) with PHP3 all works fine
2) without PHP all works fine
3) PHP4 is able to break Apache output headers (due to its ability to change
Content-Type)
4) Apache level authorization seems to be work as required since it supplies the right
Error page at first stage (consequently, it has recognized .htaccess content).
I consider there's a bug in headers processing, look:
===============================
telnet www.fis.ru 8080
Trying 212.20.24.193...
Connected to relay.fis.nsk.su.
Escape character is '^]'.
get /val/val/ http/1.0
HTTP/1.1 200 OK
Date: Fri, 04 Aug 2000 02:22:14 GMT
Server: Apache/1.3.12 (Unix) PHP/4.0.1pl2 rus/PL29.4
X-Powered-By: PHP/4.0.1pl2
Connection: close
Content-Type: text/html
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Last-Modified: Fri, 04 Aug 2000 02:22:15 GMT
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">
<HTML>
<HEAD>
<TITLE>ÎØÈÁÊÀ</TITLE>
<LINK href="/Gi/Error/page.css" rel=stylesheet type=text/css>
[further there Error explanation follows - snipped]
================================
now the right one:
================================
telnet www.fis.ru 80
Trying 212.20.24.193...
Connected to relay.fis.nsk.su.
Escape character is '^]'.
get /val/val/ http/1.0
HTTP/1.1 401 Authorization Required
Date: Fri, 04 Aug 2000 02:25:03 GMT
Server: Apache/1.3.12 (Unix) PHP/3.0.16 rus/PL29.4
X-Powered-By: PHP/3.0.16
Connection: close
Content-Type: text/html
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Last-Modified: Fri, 04 Aug 2000 02:25:05 GMT
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">
<HTML>
<HEAD>
<TITLE>ÎØÈÁÊÀ</TITLE>
<LINK href="/Gi/Error/page.css" rel=stylesheet type=text/css>
[further there Error explanation follows - snipped]
==================================
The difference consist in HTTP/1.1 200 OK header which is essentially illegal here.
As a result, users see "Access denied" without prompting by their browsers to give
credentials though the browsers suppose that's OK. Bad.
I guess the problem maybe not in PHP4 itself but in the way how it makes calls to libraries.
Does it possible to give me a hint where could be cause?
Full Bug description available at: http://bugs.php.net/?id=5942