Doc #77889 [Nab->ReO]: URL in Location header not used

From: Date: Tue, 16 Feb 2021 17:55:36 +0000
Subject: Doc #77889 [Nab->ReO]: URL in Location header not used
References: 1  Groups: php.doc.bugs 
Request: Send a blank email to doc-bugs+get-18558@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=77889&edit=1 ID: 77889 Updated by: cmb@php.net Reported by: ASchmidt at Anamera dot net Summary: URL in Location header not used -Status: Not a bug +Status: Re-Opened Type: Documentation Problem Package: Streams related Operating System: Windows x64 PHP Version: 7.2.17 Assigned To: cmb Block user comment: N Private report: N New Comment: > Dear "rtrtrtrtrt@dfdfdfdf.dfd35", […] Just ignore this troll, please. > The net effect of this issue is that the "Host" header and the > "follow_location" option are mutually exclusive, […] Not necessarily. Consider a redirect from http://example.com/old to http://example.com/new. Anyway, adding some info regarding this issue to the docs certainly won't hurt. Previous Comments: ------------------------------------------------------------------------ [2021-02-16 17:00:41] ASchmidt at Anamera dot net Dear "rtrtrtrtrt@dfdfdfdf.dfd35", thatnk you for your comment. >> there is no point to set a Host-Header and a Location-Header with different values << There appears to be confusion on how HTTP works. The "Host" header is a REQUEST header, set by the application (the PHP script). The "Location" header is a RESPONSE header set by the contacted host. The whole POINT of a server's "Location" response is to advise the client of a DIFFERENT URL (possibly involving a different "Host"!) that should be contacted. The Location response being different from the originally requested is not "garbage in/out", but intended behavior!? A PHP script does not know in advance that it will receive a "Location" response. The net effect of this issue is that the "Host" header and the "follow_location" option are mutually exclusive, which should be explicitly stated. ------------------------------------------------------------------------ [2021-02-16 16:44:24] cmb@php.net The documentation states[1]: | Values in this option will override other values (such as | User-agent:, Host:, and Authentication:). In other words, as soon as you set any custom headers, it is your responsibility that they are suitable. [1] <https://www.php.net/manual/en/context.http.php#refsect1-context.http-options> ------------------------------------------------------------------------ [2021-02-16 16:40:15] rtrtrtrtrt at dfdfdfdf dot dfd35 > it would mean that PHP is responsible for replacing > any previous, obsolete "Host" header, with the correct, > valid Host header to match the "Location" response no, it's a programming language garbage in, garbage out there is no point to set a Host-Header and a Location-Header with different values and a programming language is expected to do what you say - even if it's wrong ------------------------------------------------------------------------ [2021-02-16 16:23:57] ASchmidt at Anamera dot net Since this is not intuitive (and the default setting of follow-location=true effectively bars the use of the "Host:" header), I have submitted a comment to the manual page https://www.php.net/manual/en/context.http.php. However, as far as the PHP behavior NOT being a bug, HTTP 1.1 made "Host" headers mandatory, and more than ONE Host header is explicitly disallowed (https://tools.ietf.org/html/rfc7230#section-5.4). Standards further explicitly require that "Host" headers are to be replaced, e.g., the original "Host" must NOT not be forwarded (the example of Proxy servers is being cited.) While I understand/appreciate the "explanation" (work-around), I believe the old PHP behavior is both unexpected, and not consistent with the RFC: - Since every HTTP 1.1 request must have exactly ONE, and VALID, "Host" header that matches the intended target host, and - since PHP creates the secondary HTTP request to "follow-location", - it would mean that PHP is responsible for replacing any previous, obsolete "Host" header, with the correct, valid Host header to match the "Location" response. Otherwise the resulting "follow-location" request is not compliant with HTTP 1.1 standards. ------------------------------------------------------------------------ [2021-02-16 14:59:41] cmb@php.net Since you're explicitly setting the Host, finecars.cc is used for all requests, resulting in the undesired behavior. Just remove that entry from the headers array. ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=77889 -- Edit this bug report at https://bugs.php.net/bug.php?id=77889&edit=1

« previous php.doc.bugs (#18558) next »