Bug #51210 [Opn->Ana]: request_order prevents _COOKIE populating _REQUEST
| From: | rasmus@php.net | Date: | Fri, 05 Mar 2010 04:10:50 +0000 |
| Subject: | Bug #51210 [Opn->Ana]: request_order prevents _COOKIE populating _REQUEST | ||
| References: | 1 | Groups: | php.doc.bugs |
| Request: | Send a blank email to doc-bugs+get-4012@lists.php.net to get a copy of this message | ||
Edit report at http://bugs.php.net/bug.php?id=51210&edit=1
ID: 51210
Updated by: rasmus@php.net
Reported by: phplasma at gmail dot com
Summary: request_order prevents _COOKIE populating _REQUEST
-Status: Open
+Status: Analyzed
Type: Bug
-Package: *Configuration Issues
+Package: Documentation problem
Operating System: any
PHP Version: 5.3.1
New Comment:
No, the documentation needs to be updated. Having cookies in $_REQUEST
can cause
security problems in some circumstances and we need to get people to
stop relying
on that. It was very much intentional that the default config does not
include
cookies.
Previous Comments:
------------------------------------------------------------------------
[2010-03-05 05:07:14] phplasma at gmail dot com
Description:
------------
PHP 5.3 introduced a new configuration option named 'request_order'.
# Added "request_order" INI variable to control specifically _REQUEST
behavior. (Stas)"
http://www.php.net/ChangeLog-5.php#5.3.0
It's default value within php.ini (and related comments) are:
--
; This directive determines which super global data (G,P,C,E & S)
should
; be registered into the super global array REQUEST. If so, it also
determines
; the order in which that data is registered. The values for this
directive are
; specified in the same manner as the variables_order directive, EXCEPT
one.
; Leaving this value empty will cause PHP to use the value set in the
; variables_order directive. It does not mean it will leave the super
globals
; array REQUEST empty.
; Default Value: None
; Development Value: "GP"
; Production Value: "GP"
; http://www.php.net/manual/en/ini.core.php#ini.request-order
request_order = "GP"
--
This variable omits 'C' for COOKIES.
Versions prior to PHP 5.3 merged the contents of the _COOKIE array into
_REQUEST.
Due to this default configuration change, _REQUEST can no longer be used
to access cookie values without modifying the request_order php.ini
variable.
This changes how _REQUEST is used in PHP 5.3 by default.
This appears to be an oversight/bug, because the PHP documentation still
indicates that _REQUEST can be used to access cookies.
" An associative array that by default contains the contents of _GET,
_POST and _COOKIE. "
http://au2.php.net/manual/en/reserved.variables.request.php
Suggested Fix: Update PHP 5.3's default php.ini configuration file to
have 'GPC' instead of 'GP' for 'request_order', to restore prior
functionality.
Test script:
---------------
http://pastebin.com/MmwkU0Z3
Expected result:
----------------
The line '_REQUEST has the cookie, no bug present.' because the default
php.ini config value for request_order should be 'GPC' to include
cookies.
Actual result:
--------------
The line '_REQUEST is missing TestCookie, there is a bug.' because the
default php.ini config value for request_order currently omits cookies
('GP').
------------------------------------------------------------------------
--
Edit this bug report at http://bugs.php.net/bug.php?id=51210&edit=1