Location string in headers vary with HTTP 1.0 and 1.1 as built by PHPLIB's session start()
| From: | Brandeis Alumni Relations Webmaster | Date: | Wed, 04 Aug 1999 17:55:08 +0000 |
| Subject: | Location string in headers vary with HTTP 1.0 and 1.1 as built by PHPLIB's session start() | ||
| Groups: | php.dev | ||
| Request: | Send a blank email to php-dev+get-9506@lists.php.net to get a copy of this message | ||
Hi there,
A fellow sysadmin here at the university noticed the following behaviour,
which shows up on the new website I am building for our Alumni Relations
using php3 and phplib:
In his words:
"I noticed this while testing the DNS management stuff. I don't think it
affects any clients adversely -- lynx works -- but it's odd.
GET /bafe/firsttime/ HTTP/1.0
HTTP/1.1 302 Found
Date: Wed, 04 Aug 1999 16:03:07 GMT
Server: Apache/1.3.6 (Unix) PHP/3.0.11 mod_ssl/2.3.9 OpenSSL/0.9.3a
Status: 302 Moved Temporarily
Location:
http:///bafe/firsttime/index.php3?Bafe_Session=fac8094f683b9d1551396ee800afe
bb4
------
^^^^^^ that's the part we were concerned with
GET /bafe/firsttime/ HTTP/1.1
Host: alumni
HTTP/1.1 302 Found
Date: Wed, 04 Aug 1999 16:05:47 GMT
Server: Apache/1.3.6 (Unix) PHP/3.0.11 mod_ssl/2.3.9 OpenSSL/0.9.3a
Status: 302 Moved Temporarily
Location:
http://alumni/bafe/firsttime/index.php3?Bafe_Session=be17efbb0cc20f5fc6db797
cd77cb5c4"
-- soo.. I decided to dig in the code for php and phplib, and found the
relevant part that outputs this header, within
function start($sid = "") in session.inc from phplib.
The header is build from a line:
header("Location: ". $PROTOCOL. "://". $HTTP_HOST.$this->self_url());
however, for some reason under HTTP/1.0 "$HTTP_HOST" is an empty string at
this point? Unless that's what it should be? (that's my main ignorance point
here - so I'm either finding a bug, or just discovering 'behavior')
SO to fix for this 'bug' , this is what I did: replace that one liner with:
## Patch for http_host dissapearance under http 1.0 requests
if ($SERVER_PROTOCOL == 'HTTP/1.0') {
header("Location: ". $PROTOCOL. "://".
$SERVER_NAME.$this->self_url());
} else {
header("Location: ". $PROTOCOL. "://". $HTTP_HOST.$this->self_url());
}
with global 's added for SERVER_PROTOCOL and SERVER_NAME ... also I'm sure
something could be done better ; isn't SERVER_NAME set from apache's
configuration, and thus *could* potentially be bogus?
I would appreciate replies CC'd by email because I subscribe to neither of
these mailing lists yet.
Thank you,
Eddie Galvez
Webmaster Alumni Relations
http://www.brandeis.edu/alumni