#47083 [Opn->Csd]: Making documentation of header()'s behaviour on Location: headers more specific

From: Date: Fri, 08 May 2009 19:35:00 +0000
Subject: #47083 [Opn->Csd]: Making documentation of header()'s behaviour on Location: headers more specific
References: 1  Groups: php.doc.bugs 
Request: Send a blank email to doc-bugs+get-2223@lists.php.net to get a copy of this message
ID: 47083 Updated by: danbrown@php.net Reported By: skrebbel at gmail dot com -Status: Open +Status: Closed Bug Type: Documentation problem Operating System: N/A PHP Version: Irrelevant New Comment: In my opinion, based upon my understanding of this bug report, the manual entry describes this sufficiently - for the scope of the documentation itself - in the following paragraph: 'The second special case is the "Location:" header. Not only does it send this header back to the browser, but it also returns a REDIRECT (302) status code to the browser unless some 3xx status code has already been set.' Beyond that, I feel that your contribution in the form of a user note was appropriate for the type of material. Should you be so inclined as to resubmit the note, we'll make sure it is not rejected this time (though if it mentions key terms that indicate the manual is not correct, it may be rejected by another editor in the future to be reported again as a bug). Thanks for your contribution and follow-ups. We greatly appreciate your efforts in support of PHP! Previous Comments: ------------------------------------------------------------------------ [2009-01-13 09:47:50] skrebbel at gmail dot com Description: ------------ Note: I added the following as a manual note first, but Thiago Henrique Pojda of php-notes rejected it with the recommendation that I file it as a documentation bug. I make my conclusions based on http://cvs.php.net/viewvc.cgi/php-src/main/SAPI.c?revision=1.232&view=markup. ---- The manual is not completely precise on what PHP does (at least according to the PHP source in CVS) with Location: headers. This is the actual behaviour when you specify a Location: header, as far as I could derive: - If in earlier header() calls(*), a status code 201 or 300 - 307 was already specified, then that status code is retained - If no status code was specified, or if the status code specified earlier is not 201 or 300 ... 307 then: - If the request method is GET or HEAD then 302 "Found" is set - Otherwise (i.e. for POST or PUT), 303 "See Also" is set. Finally, if in the same header call you specify a custom status code, that one is always set (no matter its value), unless changed later again. Examples: <?php header("Location: http://www.foobar.com/"); ?> and <?php header("HTTP/1.1 404 Not Found"); header("Location: http://www.foobar.com/"); ?> set the status code to 302 when called with GET and to 303 when called with POST, and <?php header("Location: http://www.foobar.com/", true, 404); ?> and <?php header("Location: http://www.foobar.com/"); header("HTTP/1.1 404 Not Found"); ?> set the status code to 404. Note that combining a Location header with a status code other than 201 or 3xx does not really make much sense in HTTP <= 1.1 (hence PHP's behaviour); as such, the last three examples are just for illustrative purposes. (*) either through a header("HTTP/1.1 302 Found") - style call or through the third argument on a different header() call, i.e. header("Content-type: text/html", true, 302); (which does not make much sense, though) ------------------------------------------------------------------------ -- Edit this bug report at http://bugs.php.net/?id=47083&edit=1

« previous php.doc.bugs (#2223) next »