Bug #51210 [Opn->Ana]: request_order prevents _COOKIE populating _REQUEST

From: Date: Fri, 05 Mar 2010 04:10:50 +0000
Subject: Bug #51210 [Opn->Ana]: request_order prevents _COOKIE populating _REQUEST
References: 1  Groups: php.doc.bugs 
Request: Send a blank email to doc-bugs+get-4012@lists.php.net to get a copy of this message
Edit report at http://bugs.php.net/bug.php?id=51210&edit=1 ID: 51210 Updated by: rasmus@php.net Reported by: phplasma at gmail dot com Summary: request_order prevents _COOKIE populating _REQUEST -Status: Open +Status: Analyzed Type: Bug -Package: *Configuration Issues +Package: Documentation problem Operating System: any PHP Version: 5.3.1 New Comment: No, the documentation needs to be updated. Having cookies in $_REQUEST can cause security problems in some circumstances and we need to get people to stop relying on that. It was very much intentional that the default config does not include cookies. Previous Comments: ------------------------------------------------------------------------ [2010-03-05 05:07:14] phplasma at gmail dot com Description: ------------ PHP 5.3 introduced a new configuration option named 'request_order'. # Added "request_order" INI variable to control specifically _REQUEST behavior. (Stas)" http://www.php.net/ChangeLog-5.php#5.3.0 It's default value within php.ini (and related comments) are: -- ; This directive determines which super global data (G,P,C,E & S) should ; be registered into the super global array REQUEST. If so, it also determines ; the order in which that data is registered. The values for this directive are ; specified in the same manner as the variables_order directive, EXCEPT one. ; Leaving this value empty will cause PHP to use the value set in the ; variables_order directive. It does not mean it will leave the super globals ; array REQUEST empty. ; Default Value: None ; Development Value: "GP" ; Production Value: "GP" ; http://www.php.net/manual/en/ini.core.php#ini.request-order request_order = "GP" -- This variable omits 'C' for COOKIES. Versions prior to PHP 5.3 merged the contents of the _COOKIE array into _REQUEST. Due to this default configuration change, _REQUEST can no longer be used to access cookie values without modifying the request_order php.ini variable. This changes how _REQUEST is used in PHP 5.3 by default. This appears to be an oversight/bug, because the PHP documentation still indicates that _REQUEST can be used to access cookies. " An associative array that by default contains the contents of _GET, _POST and _COOKIE. " http://au2.php.net/manual/en/reserved.variables.request.php Suggested Fix: Update PHP 5.3's default php.ini configuration file to have 'GPC' instead of 'GP' for 'request_order', to restore prior functionality. Test script: --------------- http://pastebin.com/MmwkU0Z3 Expected result: ---------------- The line '_REQUEST has the cookie, no bug present.' because the default php.ini config value for request_order should be 'GPC' to include cookies. Actual result: -------------- The line '_REQUEST is missing TestCookie, there is a bug.' because the default php.ini config value for request_order currently omits cookies ('GP'). ------------------------------------------------------------------------ -- Edit this bug report at http://bugs.php.net/bug.php?id=51210&edit=1

« previous php.doc.bugs (#4012) next »