Doc #68614 [NEW]: $_SERVER['HTTP_ORIGIN'] not documented

From: Date: Tue, 16 Dec 2014 09:24:40 +0000
Subject: Doc #68614 [NEW]: $_SERVER['HTTP_ORIGIN'] not documented
Groups: php.doc.bugs 
Request: Send a blank email to doc-bugs+get-11738@lists.php.net to get a copy of this message
From: phpnet at fpierrat dot fr Operating system: n/d PHP version: Irrelevant Package: HTTP related Bug Type: Documentation Problem Bug description:$_SERVER['HTTP_ORIGIN'] not documented Description: ------------ Hi, I couldn't find any piece oh information on php.net (french) about $_SERVER['HTTP_ORIGIN']. I need it for some tests before sending an "Access-Control-Allow-Origin" header for cross-domain ajax requests: Requests can be sent from different hosts, I must identify the sending host, check if allowed against an array of allowed domains, and if ok, send this header with the return to the request. In particularly need information about following points: - when is this superglobal set? when is it NOT set? Do specific values exist (null, empty string?)? - is it always reliable or client/browser dependant? - besides, some information about its content would be appreciated, but maybe it's http more than php documentation: is the subdomain, the protocol and/or the port important for the client to be able to get the ajax return? For instance, a request sent from a https://www.example.com hosted page and a header allowing http://example.com are they compatible? Hereunder a little extract of code, to show how I need to use it. It works in my tests, but I'm not sure it's not problematic with other browsers... Test script: --------------- if(isset($_SERVER['HTTP_ORIGIN'])) {// in case of cross domain ajax call $http_origin = $_SERVER['HTTP_ORIGIN']; if(in_array($http_origin, $ajaxAllowedDomains)) { header("Access-Control-Allow-Origin: $http_origin"); } } -- Edit bug report at https://bugs.php.net/bug.php?id=68614&edit=1 -- Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=68614&r=trysnapshot54 Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=68614&r=trysnapshot55 Try a snapshot (trunk): https://bugs.php.net/fix.php?id=68614&r=trysnapshottrunk Fixed in SVN: https://bugs.php.net/fix.php?id=68614&r=fixed Fixed in release: https://bugs.php.net/fix.php?id=68614&r=alreadyfixed Need backtrace: https://bugs.php.net/fix.php?id=68614&r=needtrace Need Reproduce Script: https://bugs.php.net/fix.php?id=68614&r=needscript Try newer version: https://bugs.php.net/fix.php?id=68614&r=oldversion Not developer issue: https://bugs.php.net/fix.php?id=68614&r=support Expected behavior: https://bugs.php.net/fix.php?id=68614&r=notwrong Not enough info: https://bugs.php.net/fix.php?id=68614&r=notenoughinfo Submitted twice: https://bugs.php.net/fix.php?id=68614&r=submittedtwice register_globals: https://bugs.php.net/fix.php?id=68614&r=globals PHP 4 support discontinued: https://bugs.php.net/fix.php?id=68614&r=php4 Daylight Savings: https://bugs.php.net/fix.php?id=68614&r=dst IIS Stability: https://bugs.php.net/fix.php?id=68614&r=isapi Install GNU Sed: https://bugs.php.net/fix.php?id=68614&r=gnused Floating point limitations: https://bugs.php.net/fix.php?id=68614&r=float No Zend Extensions: https://bugs.php.net/fix.php?id=68614&r=nozend MySQL Configuration Error: https://bugs.php.net/fix.php?id=68614&r=mysqlcfg

« previous php.doc.bugs (#11738) next »