Doc #77889 [Nab->ReO]: URL in Location header not used
| From: | cmb@php.net | Date: | Tue, 16 Feb 2021 17:55:36 +0000 |
| Subject: | Doc #77889 [Nab->ReO]: URL in Location header not used | ||
| References: | 1 | Groups: | php.doc.bugs |
| Request: | Send a blank email to doc-bugs+get-18558@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=77889&edit=1
ID: 77889
Updated by: cmb@php.net
Reported by: ASchmidt at Anamera dot net
Summary: URL in Location header not used
-Status: Not a bug
+Status: Re-Opened
Type: Documentation Problem
Package: Streams related
Operating System: Windows x64
PHP Version: 7.2.17
Assigned To: cmb
Block user comment: N
Private report: N
New Comment:
> Dear "rtrtrtrtrt@dfdfdfdf.dfd35", [â¦]
Just ignore this troll, please.
> The net effect of this issue is that the "Host" header and the
> "follow_location" option are mutually exclusive, [â¦]
Not necessarily. Consider a redirect from http://example.com/old
to http://example.com/new.
Anyway, adding some info regarding this issue to the docs
certainly won't hurt.
Previous Comments:
------------------------------------------------------------------------
[2021-02-16 17:00:41] ASchmidt at Anamera dot net
Dear "rtrtrtrtrt@dfdfdfdf.dfd35", thatnk you for your comment.
>> there is no point to set a Host-Header and a Location-Header with different values <<
There appears to be confusion on how HTTP works. The "Host" header is a REQUEST header,
set by the application (the PHP script). The "Location" header is a RESPONSE header set by
the contacted host.
The whole POINT of a server's "Location" response is to advise the client of a
DIFFERENT URL (possibly involving a different "Host"!) that should be contacted. The
Location response being different from the originally requested is not "garbage in/out",
but intended behavior!?
A PHP script does not know in advance that it will receive a "Location" response. The net
effect of this issue is that the "Host" header and the "follow_location" option
are mutually exclusive, which should be explicitly stated.
------------------------------------------------------------------------
[2021-02-16 16:44:24] cmb@php.net
The documentation states[1]:
| Values in this option will override other values (such as
| User-agent:, Host:, and Authentication:).
In other words, as soon as you set any custom headers, it is your
responsibility that they are suitable.
[1] <https://www.php.net/manual/en/context.http.php#refsect1-context.http-options>
------------------------------------------------------------------------
[2021-02-16 16:40:15] rtrtrtrtrt at dfdfdfdf dot dfd35
> it would mean that PHP is responsible for replacing
> any previous, obsolete "Host" header, with the correct,
> valid Host header to match the "Location" response
no, it's a programming language
garbage in, garbage out
there is no point to set a Host-Header and a Location-Header with different values and a programming
language is expected to do what you say - even if it's wrong
------------------------------------------------------------------------
[2021-02-16 16:23:57] ASchmidt at Anamera dot net
Since this is not intuitive (and the default setting of follow-location=true effectively bars the
use of the "Host:" header), I have submitted a comment to the manual page https://www.php.net/manual/en/context.http.php.
However, as far as the PHP behavior NOT being a bug, HTTP 1.1 made "Host" headers
mandatory, and more than ONE Host header is explicitly disallowed
(https://tools.ietf.org/html/rfc7230#section-5.4). Standards further explicitly require that
"Host" headers are to be replaced, e.g., the original "Host" must NOT not be
forwarded (the example of Proxy servers is being cited.)
While I understand/appreciate the "explanation" (work-around), I believe the old PHP
behavior is both unexpected, and not consistent with the RFC:
- Since every HTTP 1.1 request must have exactly ONE, and VALID, "Host" header that
matches the intended target host, and
- since PHP creates the secondary HTTP request to "follow-location",
- it would mean that PHP is responsible for replacing any previous, obsolete "Host"
header, with the correct, valid Host header to match the "Location" response.
Otherwise the resulting "follow-location" request is not compliant with HTTP 1.1
standards.
------------------------------------------------------------------------
[2021-02-16 14:59:41] cmb@php.net
Since you're explicitly setting the Host, finecars.cc is used for
all requests, resulting in the undesired behavior. Just remove
that entry from the headers array.
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=77889
--
Edit this bug report at https://bugs.php.net/bug.php?id=77889&edit=1