Doc #66398 [NEW]: Clarify $_SERVER['HTTPS'] expected value with SSL-termination load balancer

From: Date: Fri, 03 Jan 2014 10:21:04 +0000
Subject: Doc #66398 [NEW]: Clarify $_SERVER['HTTPS'] expected value with SSL-termination load balancer
Groups: php.doc.bugs 
Request: Send a blank email to doc-bugs+get-10793@lists.php.net to get a copy of this message
From: bercheg at gmail dot com Operating system: PHP version: Irrelevant Package: Documentation problem Bug Type: Documentation Problem Bug description:Clarify $_SERVER['HTTPS'] expected value with SSL-termination load balancer Description: ------------ --- From manual page: http://www.php.net/reserved.variables.server --- It is pretty common for apps accessed by HTTPS to sit behind a load balancer that terminates the SSL connection and issue an plain HTTP request setting the X-FORWARDED-PROTO headers. See http://docs.aws.amazon.com/ElasticLoadBalancing/latest/DeveloperGuide/TerminologyandKeyConcepts.html#x-forwarded-headers and http://docs.aws.amazon.com/ElasticLoadBalancing/latest/DeveloperGuide/TerminologyandKeyConcepts.html#x-forwarded-headers The documentation at http://www.php.net/reserved.variables.server states:"'HTTPS' Set to a non-empty value if the script was queried through the HTTPS protocol. " but does not precise whether this variable is expected to be set when the X-FORWARDED-PROTO=HTTPS header was present, or more generally if the request was received through SSL-termination load balancer effectively making it secure. As a result of this lack of precision in the documentation: - some php web frameworks (e.g. http://symfony.com/doc/current/components/http_foundation/trusting_proxies.html ) implement the logic themselves by testing the $SERVER['X-FORWARDED-PROTO'] variable. - some php apps that rely on $SERVER['HTTPS'] without testing against $SERVER['X-FORWARDED-PROTO'] might incorrectly assume they are queries in HTTP format, e.g. https://github.com/commandprompt/phpldapadmin/issues/1 - some php infrastructure providers (e.g. Cloud platform-as-a-service) are not clear on whether to automatically set $SERVER['HTTPS'] upon presence of X-FORWARDED-PROTO HTTP header when it is trusted to represent the originally received protocol for the request. Suggested fix to documentation: "'HTTPS' Set to a non-empty value if the script was queried through the HTTPS protocol, directly or through a trusted upstream SSL-termination load balancer. " -- Edit bug report at https://bugs.php.net/bug.php?id=66398&edit=1 -- Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=66398&r=trysnapshot54 Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=66398&r=trysnapshot55 Try a snapshot (trunk): https://bugs.php.net/fix.php?id=66398&r=trysnapshottrunk Fixed in SVN: https://bugs.php.net/fix.php?id=66398&r=fixed Fixed in release: https://bugs.php.net/fix.php?id=66398&r=alreadyfixed Need backtrace: https://bugs.php.net/fix.php?id=66398&r=needtrace Need Reproduce Script: https://bugs.php.net/fix.php?id=66398&r=needscript Try newer version: https://bugs.php.net/fix.php?id=66398&r=oldversion Not developer issue: https://bugs.php.net/fix.php?id=66398&r=support Expected behavior: https://bugs.php.net/fix.php?id=66398&r=notwrong Not enough info: https://bugs.php.net/fix.php?id=66398&r=notenoughinfo Submitted twice: https://bugs.php.net/fix.php?id=66398&r=submittedtwice register_globals: https://bugs.php.net/fix.php?id=66398&r=globals PHP 4 support discontinued: https://bugs.php.net/fix.php?id=66398&r=php4 Daylight Savings: https://bugs.php.net/fix.php?id=66398&r=dst IIS Stability: https://bugs.php.net/fix.php?id=66398&r=isapi Install GNU Sed: https://bugs.php.net/fix.php?id=66398&r=gnused Floating point limitations: https://bugs.php.net/fix.php?id=66398&r=float No Zend Extensions: https://bugs.php.net/fix.php?id=66398&r=nozend MySQL Configuration Error: https://bugs.php.net/fix.php?id=66398&r=mysqlcfg

« previous php.doc.bugs (#10793) next »