Doc #61131 [Opn->Nab]: "HTTP-Posting-Client" etc are undocumented

From: Date: Sat, 18 Feb 2012 04:45:07 +0000
Subject: Doc #61131 [Opn->Nab]: "HTTP-Posting-Client" etc are undocumented
References: 1  Groups: php.doc.bugs 
Request: Send a blank email to doc-bugs+get-7971@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=61131&edit=1 ID: 61131 Updated by: rasmus@php.net Reported by: php at richardneill dot org Summary: "HTTP-Posting-Client" etc are undocumented -Status: Open +Status: Not a bug Type: Documentation Problem Package: Documentation problem PHP Version: Irrelevant Block user comment: N Private report: N New Comment: They aren't documented because we don't add them. Your PHP is either patched locally to do this, something else is adding it, or you have userspace code doing it. The only header PHP optionally adds (disabled by default) is X-PHP-Originating- Script which is documented here: http://www.php.net/manual/en/mail.configuration.php Previous Comments: ------------------------------------------------------------------------ [2012-02-18 04:27:03] php at richardneill dot org Description: ------------ I've just been looking at the headers of some email sent out by my own system (using PHP's mail() function). I note that the email contains headers including the following: HTTP-Posting-Client: USERS_IP_ADDRESS HTTP-Posting-URI: MY_WEBSITE:80/PATH/TO/FILE.php HTTP-Posting-User-Agent: Mozilla/5.0 (compatible; Konqueror/4.6; Linux) KHTML/4.6.5 (like Gecko) Mageia/4.6.5-1.3.mga1 I can't locate any documentation of where these headers get added, or how to configure them (despite already searching the entire PHP documentation, and grepping the php.ini files) I'm filing this first as a documentation "bug", though I really consider it as a significant security hole / information leak which could compromise the privacy of the sender. ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=61131&edit=1

« previous php.doc.bugs (#7971) next »