Bug->Doc #49184 [Ver]: INPUT_SERVER returns NULL for set variables (CLI)
| From: | cmb@php.net | Date: | Thu, 05 Aug 2021 11:13:19 +0000 |
| Subject: | Bug->Doc #49184 [Ver]: INPUT_SERVER returns NULL for set variables (CLI) | ||
| References: | 1 | Groups: | php.doc.bugs |
| Request: | Send a blank email to doc-bugs+get-19039@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=49184&edit=1
ID: 49184
Updated by: cmb@php.net
Reported by: m dot kurzyna at crystalpoint dot pl
Summary: INPUT_SERVER returns NULL for set variables (CLI)
Status: Verified
-Type: Bug
+Type: Documentation Problem
Package: Filter related
Operating System: *
PHP Version: 5.*, 6 (2009-08-07)
Block user comment: N
Private report: N
New Comment:
Each SAPI can set up additional $_SERVER variables by implementing
the respective hook[1]. The cli SAPI, for instance, adds all
environment variables to $_SERVER[2]. The filter extension,
however, does not use $_SERVER, because it may have been modified
by userland code. Instead it offers another hook for SAPIs[3], so
these can register variables to be available via INPUT_SERVER.
The cli SAPI only registers five variables with the filter
extension[4]. I don't know why it has been designed this way, but
obviously we can't change it at this point in time for BC reasons.
Thus, we should fix the documentation, which is indeed misleading.
[1] <https://github.com/php/php-src/blob/php-7.4.22/main/SAPI.h#L242>
[2] <https://github.com/php/php-src/blob/php-7.4.22/sapi/cli/php_cli.c#L334-L337>
[3] <https://github.com/php/php-src/blob/php-7.4.22/main/SAPI.h#L263>
[4] <https://github.com/php/php-src/blob/php-7.4.22/sapi/cli/php_cli.c#L341-L359>
Previous Comments:
------------------------------------------------------------------------
[2020-05-29 23:06:31] progr-d at yandex dot ru
var_dump(filter_input(INPUT_SERVER, 'SERVER_NAME'));
var_dump($_SERVER['SERVER_NAME']);
Result
------
string(0) ""
string(13) "tmp.localhost"
PHP 7.3.11, macOS X, Laravel Valet development web-server
------------------------------------------------------------------------
[2020-05-07 19:01:38] alexinbeijing at gmail dot com
Is this as simple as I think it is...?
filter_input() can pull variables from several different "groups", which you can choose
using INPUT_GET, INPUT_POST, INPUT_SERVER, INPUT_ENV, and so on.
Looking at the source code for the PHP interpreter, it looks like environment variables are not
accessed with INPUT_SERVER but rather INPUT_ENV. Actually, if you run the repro code using
INPUT_ENV, it works.
Probably people assumed that the variables in $_SERVER should be accessible using INPUT_SERVER. It
seems that's not the case.
The documentation seems to be faulty, in that it doesn't explain what variables can actually be
accessed through INPUT_SERVER. I can see some of them in the source code for the interpreter, like
"PHP_AUTH_USER", "PHP_AUTH_PW", "PHP_AUTH_DIGEST",
"REQUEST_TIME_FLOAT", "REQUEST_TIME", and so on. You can also get
"SCRIPT_NAME", "SCRIPT_FILENAME", "DOCUMENT_ROOT", etc.
Looking in Google, the Internet seems to be half covered with erroneous statements that
filter_input(INPUT_SERVER, ...) doesn't work. I wonder why nobody ever stepped in to explain?
If I'm off base, please straighten me out!
------------------------------------------------------------------------
[2018-12-11 20:48:57] zoon01 at xigmanas dot com
Also this is a problem with the 7.3.0 release.
------------------------------------------------------------------------
[2018-01-12 19:43:34] m dot patrushev at pitanik dot de
still a problem in 2018 on Versions:
5.6.30
7.1.10
------------------------------------------------------------------------
[2017-01-23 07:44:48] dclarke at blastwave dot org
Still a valid bug in 5.6.30 :
bash-4.3$ ./php-5.6.30_SunOS5.10_sparcv9.001/sapi/cli/php --version
PHP 5.6.30 (cli) (built: Jan 23 2017 01:16:31)
Copyright (c) 1997-2016 The PHP Group
Zend Engine v2.6.0, Copyright (c) 1998-2016 Zend Technologies
bash-4.3$ cat foo_var_dump.php
<?php
var_dump(
filter_input(INPUT_SERVER,'SOME_ENV_NAME',
FILTER_SANITIZE_STRING),
$_SERVER['SOME_ENV_NAME'] );
?>
bash-4.3$ SOME_ENV_NAME=this_stuff ./php-5.6.30_SunOS5.10_sparcv9.001/sapi/cli/php foo_var_dump.php
NULL
string(10) "this_stuff"
It may be worth running a trace through the calls and I did build
with full debug sysmbols so this is possible. At least on Solaris.
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=49184
--
Edit this bug report at https://bugs.php.net/bug.php?id=49184&edit=1