Doc #61893 [ReO->Csd]: The $_REQUEST Predefined Variable Does NOT Contains the Contents of $_COOKIE

From: Date: Wed, 09 Oct 2013 06:23:52 +0000
Subject: Doc #61893 [ReO->Csd]: The $_REQUEST Predefined Variable Does NOT Contains the Contents of $_COOKIE
References: 1  Groups: php.doc.bugs 
Request: Send a blank email to doc-bugs+get-10451@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=61893&edit=1

 ID:                 61893
 Updated by:         krakjoe@php.net
 Reported by:        marcoscanrib at ig dot com dot br
 Summary:            The $_REQUEST Predefined Variable Does NOT Contains
                     the Contents of $_COOKIE
-Status:             Re-Opened
+Status:             Closed
 Type:               Documentation Problem
 Package:            Documentation problem
 Operating System:   Windows XP Prof
 PHP Version:        5.3Git-2012-05-02 (Git)
-Assigned To:        
+Assigned To:        krakjoe
 Block user comment: N
 Private report:     N

 New Comment:

_REQUEST contains the *REQUEST* cookies, you should not expect to find your *RESPONSE* in _REQUEST
...

I don't see that there is a problem, closing the bug.


Previous Comments:
------------------------------------------------------------------------
[2012-08-28 18:54:32] philip@php.net

The meaning of "default" here is debatable and will never please everyone. But 
the request_order documentation shows "" as its default, but does also refer to 
the distributed php.ini-* files. 

The default value is what PHP would do without a php.ini file. Different 
distributions (Linux variants, or packages like the aforementioned XAMPP, and the 
like) choose either php.ini-production/php.ini-recommended, or use neither, or 
sets custom values, so really the meaning of "default" is unclear. This is why we 
use the non-php.ini value as the default. It's simple.

And just to be clear. PHP does not ship with a "php.ini" file as instead one must 
manually rename one of the two example files.

But that description is unclear so this bug report now requests that:

A) This be rewritten "Note that the default distribution php.ini files does not 
contain the 'C' for cookies, due to security concerns." as it's strange.

B) We have a FAQ entry about what a "default" value means. One that is more 
descriptive than our current docs on the matter. It should refer to both php.ini-
* files, that default is non-php.ini, and maybe even mention the -n cli option.

I thought we already did something like (B) but I cannot find.

------------------------------------------------------------------------
[2012-08-28 14:23:47] kim dot rowan at cancer dot org dot uk

I would also like to see the documentation updated to reflect the accurate circumstances where
$_REQUEST would incorporate $_COOKIE data alongside $_GET and $_POST as it is currently misleading.

------------------------------------------------------------------------
[2012-05-03 02:24:00] marcoscanrib at ig dot com dot br

I have just searched the documentation for the 'request_order' directive and it 
clearly states : "Note that the >>default<< distribution php.ini files does not 
contain the 'C' for cookies". 

So, I believe this proves that, >>by default<<, $_REQUEST does NOT include the 
contents of $_COOKIE and that the following statement in the documentation is 
wrong and should be fixed : "Description : An associative array that by default 
contains the contents of $_GET, $_POST and $_COOKIE."

------------------------------------------------------------------------
[2012-05-03 02:08:36] marcoscanrib at ig dot com dot br

Congratulations for the quick follow up of the users feedbacks. 

About your follow up content, I add that I have not used variables_order nor 
request_order to change the default behavior of the $_REQUEST array and I got the 
results I stated. So, at least in my PHP installation (XAMPP), the default 
behavior of the $_REQUEST is NOT to include the contents of $_COOKIE. Is there a 
way to check if XAMPP changed the default behaviour of the $_REQUEST array ?

------------------------------------------------------------------------
[2012-05-02 01:22:05] aharvey@php.net

The documentation already states clearly that that's the default behaviour only 
and can be changed via variables_order and request_order.

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=61893


-- 
Edit this bug report at https://bugs.php.net/bug.php?id=61893&edit=1


Thread (7 messages)

« previous php.doc.bugs (#10451) next »