Doc #77889 [ReO->Csd]: URL in Location header not used

From: Date: Wed, 17 Feb 2021 13:28:43 +0000
Subject: Doc #77889 [ReO->Csd]: URL in Location header not used
References: 1  Groups: php.doc.bugs 
Request: Send a blank email to doc-bugs+get-18560@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=77889&edit=1 ID: 77889 Updated by: cmb@php.net Reported by: ASchmidt at Anamera dot net Summary: URL in Location header not used -Status: Re-Opened +Status: Closed Type: Documentation Problem Package: Streams related Operating System: Windows x64 PHP Version: 7.2.17 Assigned To: cmb Block user comment: N Private report: N New Comment: Automatic comment on behalf of cmbecker69@gmx.de Revision: http://git.php.net/?p=doc/en.git;a=commit;h=4dfe5cc41eabcfb5b7eb7afa194ce078ad4e1bf4 Log: Fix #77889: URL in Location header not used Previous Comments: ------------------------------------------------------------------------ [2021-02-16 18:09:20] ASchmidt at Anamera dot net >> Consider a redirect from http://example.com/old to >> http://example.com/new << Uh, please keep in mind that the PHP script would NEVER know in advance of any redirect, or, whether any such redirect would happen to only be to another path at the same host. Consequently, the script author has to ASSUME it at least possible (if not likely) that the Location header might very well supply a different host -- even if only to add/remove the "www." portion, which today is standard practice! Ergo, since a change in host name (or subdomain) does have to be allowed for under every circumstance, the "Host" header and the "follow_location" option effectively ARE mutually exclusive, if "follow_location" doesn't supersede any originally supplied host header with the host from "Location" header. ------------------------------------------------------------------------ [2021-02-16 17:55:36] cmb@php.net > Dear "rtrtrtrtrt@dfdfdfdf.dfd35", […] Just ignore this troll, please. > The net effect of this issue is that the "Host" header and the > "follow_location" option are mutually exclusive, […] Not necessarily. Consider a redirect from http://example.com/old to http://example.com/new. Anyway, adding some info regarding this issue to the docs certainly won't hurt. ------------------------------------------------------------------------ [2021-02-16 17:00:41] ASchmidt at Anamera dot net Dear "rtrtrtrtrt@dfdfdfdf.dfd35", thatnk you for your comment. >> there is no point to set a Host-Header and a Location-Header with different values << There appears to be confusion on how HTTP works. The "Host" header is a REQUEST header, set by the application (the PHP script). The "Location" header is a RESPONSE header set by the contacted host. The whole POINT of a server's "Location" response is to advise the client of a DIFFERENT URL (possibly involving a different "Host"!) that should be contacted. The Location response being different from the originally requested is not "garbage in/out", but intended behavior!? A PHP script does not know in advance that it will receive a "Location" response. The net effect of this issue is that the "Host" header and the "follow_location" option are mutually exclusive, which should be explicitly stated. ------------------------------------------------------------------------ [2021-02-16 16:44:24] cmb@php.net The documentation states[1]: | Values in this option will override other values (such as | User-agent:, Host:, and Authentication:). In other words, as soon as you set any custom headers, it is your responsibility that they are suitable. [1] <https://www.php.net/manual/en/context.http.php#refsect1-context.http-options> ------------------------------------------------------------------------ [2021-02-16 16:40:15] rtrtrtrtrt at dfdfdfdf dot dfd35 > it would mean that PHP is responsible for replacing > any previous, obsolete "Host" header, with the correct, > valid Host header to match the "Location" response no, it's a programming language garbage in, garbage out there is no point to set a Host-Header and a Location-Header with different values and a programming language is expected to do what you say - even if it's wrong ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=77889 -- Edit this bug report at https://bugs.php.net/bug.php?id=77889&edit=1

« previous php.doc.bugs (#18560) next »