Doc #66398 [NEW]: Clarify $_SERVER['HTTPS'] expected value with SSL-termination load balancer
| From: | bercheg at gmail dot com | Date: | Fri, 03 Jan 2014 10:21:04 +0000 |
| Subject: | Doc #66398 [NEW]: Clarify $_SERVER['HTTPS'] expected value with SSL-termination load balancer | ||
| Groups: | php.doc.bugs | ||
| Request: | Send a blank email to doc-bugs+get-10793@lists.php.net to get a copy of this message | ||
From: bercheg at gmail dot com
Operating system:
PHP version: Irrelevant
Package: Documentation problem
Bug Type: Documentation Problem
Bug description:Clarify $_SERVER['HTTPS'] expected value with SSL-termination load
balancer
Description:
------------
---
From manual page: http://www.php.net/reserved.variables.server
---
It is pretty common for apps accessed by HTTPS to sit behind a load
balancer that terminates the SSL connection and issue an plain HTTP
request setting the X-FORWARDED-PROTO headers.
See
http://docs.aws.amazon.com/ElasticLoadBalancing/latest/DeveloperGuide/TerminologyandKeyConcepts.html#x-forwarded-headers
and
http://docs.aws.amazon.com/ElasticLoadBalancing/latest/DeveloperGuide/TerminologyandKeyConcepts.html#x-forwarded-headers
The documentation at http://www.php.net/reserved.variables.server
states:"'HTTPS'
Set to a non-empty value if the script was queried through the HTTPS
protocol. "
but does not precise whether this variable is expected to be set when
the X-FORWARDED-PROTO=HTTPS header was present, or more generally if the
request was received through SSL-termination load balancer effectively
making it secure.
As a result of this lack of precision in the documentation:
- some php web frameworks (e.g.
http://symfony.com/doc/current/components/http_foundation/trusting_proxies.html
) implement the logic themselves by testing the
$SERVER['X-FORWARDED-PROTO'] variable.
- some php apps that rely on $SERVER['HTTPS'] without testing against
$SERVER['X-FORWARDED-PROTO'] might incorrectly assume they are queries
in HTTP format, e.g.
https://github.com/commandprompt/phpldapadmin/issues/1
- some php infrastructure providers (e.g. Cloud platform-as-a-service)
are not clear on whether to automatically set $SERVER['HTTPS'] upon
presence of X-FORWARDED-PROTO HTTP header when it is trusted to
represent the originally received protocol for the request.
Suggested fix to documentation:
"'HTTPS'
Set to a non-empty value if the script was queried through the HTTPS
protocol, directly or through a trusted upstream SSL-termination load
balancer. "
--
Edit bug report at https://bugs.php.net/bug.php?id=66398&edit=1
--
Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=66398&r=trysnapshot54
Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=66398&r=trysnapshot55
Try a snapshot (trunk): https://bugs.php.net/fix.php?id=66398&r=trysnapshottrunk
Fixed in SVN: https://bugs.php.net/fix.php?id=66398&r=fixed
Fixed in release: https://bugs.php.net/fix.php?id=66398&r=alreadyfixed
Need backtrace: https://bugs.php.net/fix.php?id=66398&r=needtrace
Need Reproduce Script: https://bugs.php.net/fix.php?id=66398&r=needscript
Try newer version: https://bugs.php.net/fix.php?id=66398&r=oldversion
Not developer issue: https://bugs.php.net/fix.php?id=66398&r=support
Expected behavior: https://bugs.php.net/fix.php?id=66398&r=notwrong
Not enough info: https://bugs.php.net/fix.php?id=66398&r=notenoughinfo
Submitted twice: https://bugs.php.net/fix.php?id=66398&r=submittedtwice
register_globals: https://bugs.php.net/fix.php?id=66398&r=globals
PHP 4 support discontinued: https://bugs.php.net/fix.php?id=66398&r=php4
Daylight Savings: https://bugs.php.net/fix.php?id=66398&r=dst
IIS Stability: https://bugs.php.net/fix.php?id=66398&r=isapi
Install GNU Sed: https://bugs.php.net/fix.php?id=66398&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=66398&r=float
No Zend Extensions: https://bugs.php.net/fix.php?id=66398&r=nozend
MySQL Configuration Error: https://bugs.php.net/fix.php?id=66398&r=mysqlcfg