Doc #60600 [Asn->Csd]: $HTTP_RAW_POST_DATA is always populated

From: Date: Thu, 27 Mar 2014 16:01:25 +0000
Subject: Doc #60600 [Asn->Csd]: $HTTP_RAW_POST_DATA is always populated
References: 1  Groups: php.doc.bugs 
Request: Send a blank email to doc-bugs+get-11099@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=60600&edit=1 ID: 60600 Updated by: mike@php.net Reported by: ercoli at gmail dot com Summary: $HTTP_RAW_POST_DATA is always populated -Status: Assigned +Status: Closed Type: Documentation Problem Package: PHP options/info functions Operating System: linux PHP Version: 5.3.8 Assigned To: mike Block user comment: N Private report: N New Comment: You can set always populate_raw_post_data to -1 in PHP-5.6 Previous Comments: ------------------------------------------------------------------------ [2014-02-01 11:54:06] krakjoe@php.net Due to recently merged RFC'd patches, this should be looked at in the context of current versions of PHP. So assigning to someone useful ... Noteworthy, the report is originally made for an unsupported, outdated version of PHP, and is not a security issue. If whatever response you get from the assigned person is not satisfactory, please consider making the bug report using a supported, stable version of PHP. Thanks for taking the time to make PHP better :) ------------------------------------------------------------------------ [2011-12-24 13:49:29] cataphract@php.net Your interpretation of "recognized MIME type" is off (only "application/x-www-form-urlencoded" and "multipart/form-data" are "recogized" in this sense) and your last sentence is also inaccurate (using php://input doesn't prevent the data from being loaded into memory; either it's already completely present in memory or otherwise it's not and it's the only the way to access the HTTP entity anyway). But in any case, the documentation is poor in this matter. Thanks ------------------------------------------------------------------------ [2011-12-23 11:23:18] ercoli at gmail dot com Description: ------------ $HTTP_RAW_POST_DATA is always populated when data is posted with content-type 'text/xml' or 'application/xml' (and enctype != "multipart/form-data" ) , even if the directive 'always_populate_raw_post_data' is set to Off. The manual says "the variable is populated only with unrecognized MIME type of the data", but as far as I can discern, 'text/xml' and 'application/xml' are both recognized mime type. The preferred method for accessing the xml POST data is php://input since we can use a streaming parser with low memory footprint. ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=60600&edit=1

« previous php.doc.bugs (#11099) next »