SAPI/Apache: Some characters in incomonig variable names are silently changed

From: Date: Fri, 16 Nov 2001 08:43:24 +0000
Subject: SAPI/Apache: Some characters in incomonig variable names are silently changed
References: 1  Groups: php.dev 
Request: Send a blank email to php-dev+get-70625@lists.php.net to get a copy of this message
Hello list,

It's fairly easy to fix this problem, by just estrdupping the keys before
passing them on onto "php_register_variabele"
(sapi/apachi/mod_php4.c:253). The problem is however where to free this
estrdupped keys again. Can somebody with some deep knowlegde of the SAPI
code look in into this?

Derick



On 7 Nov 2001 derick@php.net wrote:

> Previous Comments:
> ------------------------------------------------------------------------
>
> [2001-11-07 01:56:30] lampa@fee.vutbr.cz
>
> I don't think that FAQ solves that problem.
> Look at the source code of Apache server. There
> are several tests of the variable "force-response-1.0"
> there. The problem is not that php code variable
> is $force-response-1_0, that's OK, but the real
> problem is that apache variable name in r->subprocess_env
> is changed too. That's side effect and not pleasent.
>
> ------------------------------------------------------------------------
>
> [2001-11-06 16:30:56] jeroen@php.net
>
> This is mentioned in http://uk.php.net/manual/en/faq.html.php#AEN63677
> . Impossible to find if you don't know where to find it. So changing this to a documentation
> problem.
>
> (the issue is that invalid characters in incoming variable names, like dots, are converted to
> underscores. This happens with any incoming variable name, be it GET, POST, ENV, or whatever.)
>
> Changed subject
>
> ------------------------------------------------------------------------
>
> [2001-11-06 16:09:30] lampa@fee.vutbr.cz
>
> Apache module mod_setenvif sets variables in
> r->subprocess_env. If variable name contains character ".", then
> mod_php4.c/sapi_apache_register_server_variables() will
> replace it with "_". This breaks internal
> variables like force-response-1.0 (php changes it to
> force-response-1_0).
>
> Solution: the key in the php_register_variable() call
> should be a copy of the real key.
>
> ------------------------------------------------------------------------
>
>
>
> Edit this bug report at http://bugs.php.net/?id=13961&edit=1
>
>
> --
> PHP Development Mailing List <http://www.php.net/>
> To unsubscribe, e-mail: php-dev-unsubscribe@lists.php.net
> For additional commands, e-mail: php-dev-help@lists.php.net
> To contact the list administrators, e-mail: php-list-admin@lists.php.net
>

Derick Rethans

---------------------------------------------------------------------
        PHP: Scripting the Web - www.php.net - derick@php.net
             SRM: Site Resource Manager - www.vl-srm.net
---------------------------------------------------------------------
    JDI Media Solutions - www.jdimedia.nl - d.rethans@jdimedia.nl
     Boulevard Heuvelink 102 - 6828 KT Arnhem - The Netherlands
---------------------------------------------------------------------



Thread (6 messages)

« previous php.dev (#70625) next »