Location string in headers vary with HTTP 1.0 and 1.1 as built by PHPLIB's session start()

From: Date: Wed, 04 Aug 1999 17:55:08 +0000
Subject: Location string in headers vary with HTTP 1.0 and 1.1 as built by PHPLIB's session start()
Groups: php.dev 
Request: Send a blank email to php-dev+get-9506@lists.php.net to get a copy of this message
Hi there, A fellow sysadmin here at the university noticed the following behaviour, which shows up on the new website I am building for our Alumni Relations using php3 and phplib: In his words: "I noticed this while testing the DNS management stuff. I don't think it affects any clients adversely -- lynx works -- but it's odd. GET /bafe/firsttime/ HTTP/1.0 HTTP/1.1 302 Found Date: Wed, 04 Aug 1999 16:03:07 GMT Server: Apache/1.3.6 (Unix) PHP/3.0.11 mod_ssl/2.3.9 OpenSSL/0.9.3a Status: 302 Moved Temporarily Location: http:///bafe/firsttime/index.php3?Bafe_Session=fac8094f683b9d1551396ee800afe bb4 ------ ^^^^^^ that's the part we were concerned with GET /bafe/firsttime/ HTTP/1.1 Host: alumni HTTP/1.1 302 Found Date: Wed, 04 Aug 1999 16:05:47 GMT Server: Apache/1.3.6 (Unix) PHP/3.0.11 mod_ssl/2.3.9 OpenSSL/0.9.3a Status: 302 Moved Temporarily Location: http://alumni/bafe/firsttime/index.php3?Bafe_Session=be17efbb0cc20f5fc6db797 cd77cb5c4" -- soo.. I decided to dig in the code for php and phplib, and found the relevant part that outputs this header, within function start($sid = "") in session.inc from phplib. The header is build from a line: header("Location: ". $PROTOCOL. "://". $HTTP_HOST.$this->self_url()); however, for some reason under HTTP/1.0 "$HTTP_HOST" is an empty string at this point? Unless that's what it should be? (that's my main ignorance point here - so I'm either finding a bug, or just discovering 'behavior') SO to fix for this 'bug' , this is what I did: replace that one liner with: ## Patch for http_host dissapearance under http 1.0 requests if ($SERVER_PROTOCOL == 'HTTP/1.0') { header("Location: ". $PROTOCOL. "://". $SERVER_NAME.$this->self_url()); } else { header("Location: ". $PROTOCOL. "://". $HTTP_HOST.$this->self_url()); } with global 's added for SERVER_PROTOCOL and SERVER_NAME ... also I'm sure something could be done better ; isn't SERVER_NAME set from apache's configuration, and thus *could* potentially be bogus? I would appreciate replies CC'd by email because I subscribe to neither of these mailing lists yet. Thank you, Eddie Galvez Webmaster Alumni Relations http://www.brandeis.edu/alumni

« previous php.dev (#9506) next »