Doc #77889 [ReO]: URL in Location header not used
| From: | ASchmidt at Anamera dot net | Date: | Tue, 16 Feb 2021 18:09:20 +0000 |
| Subject: | Doc #77889 [ReO]: URL in Location header not used | ||
| References: | 1 | Groups: | php.doc.bugs |
| Request: | Send a blank email to doc-bugs+get-18559@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=77889&edit=1
ID: 77889
User updated by: ASchmidt at Anamera dot net
Reported by: ASchmidt at Anamera dot net
Summary: URL in Location header not used
Status: Re-Opened
Type: Documentation Problem
Package: Streams related
Operating System: Windows x64
PHP Version: 7.2.17
Assigned To: cmb
Block user comment: N
Private report: N
New Comment:
>> Consider a redirect from http://example.com/old to
>> http://example.com/new <<
Uh, please keep in mind that the PHP script would NEVER know in advance of any redirect, or, whether
any such redirect would happen to only be to another path at the same host.
Consequently, the script author has to ASSUME it at least possible (if not likely) that the Location
header might very well supply a different host -- even if only to add/remove the "www."
portion, which today is standard practice!
Ergo, since a change in host name (or subdomain) does have to be allowed for under every
circumstance, the "Host" header and the "follow_location" option effectively ARE
mutually exclusive, if "follow_location" doesn't supersede any originally supplied
host header with the host from "Location" header.
Previous Comments:
------------------------------------------------------------------------
[2021-02-16 17:55:36] cmb@php.net
> Dear "rtrtrtrtrt@dfdfdfdf.dfd35", [â¦]
Just ignore this troll, please.
> The net effect of this issue is that the "Host" header and the
> "follow_location" option are mutually exclusive, [â¦]
Not necessarily. Consider a redirect from http://example.com/old
to http://example.com/new.
Anyway, adding some info regarding this issue to the docs
certainly won't hurt.
------------------------------------------------------------------------
[2021-02-16 17:00:41] ASchmidt at Anamera dot net
Dear "rtrtrtrtrt@dfdfdfdf.dfd35", thatnk you for your comment.
>> there is no point to set a Host-Header and a Location-Header with different values <<
There appears to be confusion on how HTTP works. The "Host" header is a REQUEST header,
set by the application (the PHP script). The "Location" header is a RESPONSE header set by
the contacted host.
The whole POINT of a server's "Location" response is to advise the client of a
DIFFERENT URL (possibly involving a different "Host"!) that should be contacted. The
Location response being different from the originally requested is not "garbage in/out",
but intended behavior!?
A PHP script does not know in advance that it will receive a "Location" response. The net
effect of this issue is that the "Host" header and the "follow_location" option
are mutually exclusive, which should be explicitly stated.
------------------------------------------------------------------------
[2021-02-16 16:44:24] cmb@php.net
The documentation states[1]:
| Values in this option will override other values (such as
| User-agent:, Host:, and Authentication:).
In other words, as soon as you set any custom headers, it is your
responsibility that they are suitable.
[1] <https://www.php.net/manual/en/context.http.php#refsect1-context.http-options>
------------------------------------------------------------------------
[2021-02-16 16:40:15] rtrtrtrtrt at dfdfdfdf dot dfd35
> it would mean that PHP is responsible for replacing
> any previous, obsolete "Host" header, with the correct,
> valid Host header to match the "Location" response
no, it's a programming language
garbage in, garbage out
there is no point to set a Host-Header and a Location-Header with different values and a programming
language is expected to do what you say - even if it's wrong
------------------------------------------------------------------------
[2021-02-16 16:23:57] ASchmidt at Anamera dot net
Since this is not intuitive (and the default setting of follow-location=true effectively bars the
use of the "Host:" header), I have submitted a comment to the manual page https://www.php.net/manual/en/context.http.php.
However, as far as the PHP behavior NOT being a bug, HTTP 1.1 made "Host" headers
mandatory, and more than ONE Host header is explicitly disallowed
(https://tools.ietf.org/html/rfc7230#section-5.4). Standards further explicitly require that
"Host" headers are to be replaced, e.g., the original "Host" must NOT not be
forwarded (the example of Proxy servers is being cited.)
While I understand/appreciate the "explanation" (work-around), I believe the old PHP
behavior is both unexpected, and not consistent with the RFC:
- Since every HTTP 1.1 request must have exactly ONE, and VALID, "Host" header that
matches the intended target host, and
- since PHP creates the secondary HTTP request to "follow-location",
- it would mean that PHP is responsible for replacing any previous, obsolete "Host"
header, with the correct, valid Host header to match the "Location" response.
Otherwise the resulting "follow-location" request is not compliant with HTTP 1.1
standards.
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=77889
--
Edit this bug report at https://bugs.php.net/bug.php?id=77889&edit=1