Doc #68614 [NEW]: $_SERVER['HTTP_ORIGIN'] not documented
| From: | phpnet at fpierrat dot fr | Date: | Tue, 16 Dec 2014 09:24:40 +0000 |
| Subject: | Doc #68614 [NEW]: $_SERVER['HTTP_ORIGIN'] not documented | ||
| Groups: | php.doc.bugs | ||
| Request: | Send a blank email to doc-bugs+get-11738@lists.php.net to get a copy of this message | ||
From: phpnet at fpierrat dot fr
Operating system: n/d
PHP version: Irrelevant
Package: HTTP related
Bug Type: Documentation Problem
Bug description:$_SERVER['HTTP_ORIGIN'] not documented
Description:
------------
Hi,
I couldn't find any piece oh information on php.net (french) about
$_SERVER['HTTP_ORIGIN'].
I need it for some tests before sending an "Access-Control-Allow-Origin"
header for cross-domain ajax requests:
Requests can be sent from different hosts, I must identify the sending
host, check if allowed against an array of allowed domains, and if ok,
send this header with the return to the request.
In particularly need information about following points:
- when is this superglobal set? when is it NOT set? Do specific values
exist (null, empty string?)?
- is it always reliable or client/browser dependant?
- besides, some information about its content would be appreciated, but
maybe it's http more than php documentation: is the subdomain, the
protocol and/or the port important for the client to be able to get the
ajax return? For instance, a request sent from a https://www.example.com
hosted page and a header allowing http://example.com are they
compatible?
Hereunder a little extract of code, to show how I need to use it. It
works in my tests, but I'm not sure it's not problematic with other
browsers...
Test script:
---------------
if(isset($_SERVER['HTTP_ORIGIN'])) {// in case of cross domain ajax
call
$http_origin = $_SERVER['HTTP_ORIGIN'];
if(in_array($http_origin, $ajaxAllowedDomains))
{ header("Access-Control-Allow-Origin: $http_origin"); }
}
--
Edit bug report at https://bugs.php.net/bug.php?id=68614&edit=1
--
Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=68614&r=trysnapshot54
Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=68614&r=trysnapshot55
Try a snapshot (trunk): https://bugs.php.net/fix.php?id=68614&r=trysnapshottrunk
Fixed in SVN: https://bugs.php.net/fix.php?id=68614&r=fixed
Fixed in release: https://bugs.php.net/fix.php?id=68614&r=alreadyfixed
Need backtrace: https://bugs.php.net/fix.php?id=68614&r=needtrace
Need Reproduce Script: https://bugs.php.net/fix.php?id=68614&r=needscript
Try newer version: https://bugs.php.net/fix.php?id=68614&r=oldversion
Not developer issue: https://bugs.php.net/fix.php?id=68614&r=support
Expected behavior: https://bugs.php.net/fix.php?id=68614&r=notwrong
Not enough info: https://bugs.php.net/fix.php?id=68614&r=notenoughinfo
Submitted twice: https://bugs.php.net/fix.php?id=68614&r=submittedtwice
register_globals: https://bugs.php.net/fix.php?id=68614&r=globals
PHP 4 support discontinued: https://bugs.php.net/fix.php?id=68614&r=php4
Daylight Savings: https://bugs.php.net/fix.php?id=68614&r=dst
IIS Stability: https://bugs.php.net/fix.php?id=68614&r=isapi
Install GNU Sed: https://bugs.php.net/fix.php?id=68614&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=68614&r=float
No Zend Extensions: https://bugs.php.net/fix.php?id=68614&r=nozend
MySQL Configuration Error: https://bugs.php.net/fix.php?id=68614&r=mysqlcfg