Doc #68614 [Opn]: $_SERVER['HTTP_ORIGIN'] not documented
| From: | cmb@php.net | Date: | Fri, 17 Jun 2016 11:36:28 +0000 |
| Subject: | Doc #68614 [Opn]: $_SERVER['HTTP_ORIGIN'] not documented | ||
| References: | 1 | Groups: | php.doc.bugs |
| Request: | Send a blank email to doc-bugs+get-13547@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=68614&edit=1
ID: 68614
Updated by: cmb@php.net
Reported by: phpnet at fpierrat dot fr
-Summary: [FR] $_SERVER['HTTP_ORIGIN'] not documented
+Summary: $_SERVER['HTTP_ORIGIN'] not documented
Status: Open
Type: Documentation Problem
-Package: Translation problem
+Package: Documentation problem
Operating System: n/d
PHP Version: Irrelevant
Block user comment: N
Private report: N
New Comment:
It appears to me that this is not a translation issue, as the
English docs do not explain HTTP_* in general either, but only
list some common cases.
Previous Comments:
------------------------------------------------------------------------
[2014-12-16 19:52:03] aharvey@php.net
Tagging, although my guess is that this is just accounted for by whatever documentation French has
for $_SERVER variables created by HTTP headers (like Origin).
------------------------------------------------------------------------
[2014-12-16 09:24:39] phpnet at fpierrat dot fr
Description:
------------
Hi,
I couldn't find any piece oh information on php.net (french) about
$_SERVER['HTTP_ORIGIN'].
I need it for some tests before sending an "Access-Control-Allow-Origin" header for
cross-domain ajax requests:
Requests can be sent from different hosts, I must identify the sending host, check if allowed
against an array of allowed domains, and if ok, send this header with the return to the request.
In particularly need information about following points:
- when is this superglobal set? when is it NOT set? Do specific values exist (null, empty string?)?
- is it always reliable or client/browser dependant?
- besides, some information about its content would be appreciated, but maybe it's http more
than php documentation: is the subdomain, the protocol and/or the port important for the client to
be able to get the ajax return? For instance, a request sent from a https://www.example.com hosted page and a header allowing http://example.com are they compatible?
Hereunder a little extract of code, to show how I need to use it. It works in my tests, but I'm
not sure it's not problematic with other browsers...
Test script:
---------------
if(isset($_SERVER['HTTP_ORIGIN'])) {// in case of cross domain ajax call
$http_origin = $_SERVER['HTTP_ORIGIN'];
if(in_array($http_origin, $ajaxAllowedDomains))
{ header("Access-Control-Allow-Origin: $http_origin"); }
}
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=68614&edit=1