Doc #61131 [Com]: "HTTP-Posting-Client" etc are undocumented
| From: | php at richardneill dot org | Date: | Sat, 18 Feb 2012 07:06:10 +0000 |
| Subject: | Doc #61131 [Com]: "HTTP-Posting-Client" etc are undocumented | ||
| References: | 1 | Groups: | php.doc.bugs |
| Request: | Send a blank email to doc-bugs+get-7977@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=61131&edit=1
ID: 61131
Comment by: php at richardneill dot org
Reported by: php at richardneill dot org
Summary: "HTTP-Posting-Client" etc are undocumented
Status: Not a bug
Type: Documentation Problem
Package: Documentation problem
PHP Version: Irrelevant
Block user comment: N
Private report: N
New Comment:
I agree - this feature isn't very useful, even upstream.
I have found an ugly workaround: Postfix supports checking (and removing) headers. (There is
probably a similar fix for all other MTAs)
1. Enable header-checks, in /etc/postfix/main.cf :
header_checks = regexp:/etc/postfix/header_checks
2. Specify the headers to strip, in /etc/postfix/header_checks :
/^HTTP-Posting-Client:/ IGNORE
/^HTTP-Posting-URI:/ IGNORE
/^HTTP-Posting-User-Agent:/ IGNORE
Previous Comments:
------------------------------------------------------------------------
[2012-02-18 06:27:50] rasmus@php.net
I saw you mentioned it should be implemented upstream. For spam-detection
purposes, I don't think all those headers are all that useful. What you really
want to know, as an ISP, is which script on your server is being used to send
spam with. The IP and user-agent isn't all that useful and if you really want
those, you can dig them out of your access logs since you know which script was
hit. We already have that capability implemented via mail.add_x_header.
------------------------------------------------------------------------
[2012-02-18 06:20:08] php at richardneill dot org
Crossref: I've filed this for Mageia.
https://bugs.mageia.org/show_bug.cgi?id=4571
The specfile credits PLD for the original patch.
------------------------------------------------------------------------
[2012-02-18 05:51:28] rasmus@php.net
And no way to turn it off. Not a very friendly patch.
------------------------------------------------------------------------
[2012-02-18 05:42:46] php at richardneill dot org
You're right - sorry for wasting your time - this is a patch in the most unlikely place.
Mandriva (and thence Mageia) have patched the source, in file php-mail.diff; here are the relevant
lines.
+ if (PG(http_globals)[TRACK_VARS_SERVER]) {
+ zval **remote_addr, **server_name, **server_port,
+ **script_name, **http_user_agent;
+
+ if (zend_hash_find(PG(http_globals)[TRACK_VARS_SERVER]->value.ht, "REMOTE_ADDR",
sizeof("REMOTE_ADDR"), (void **) &remote_addr)==SUCCESS) {
+ convert_to_string_ex(remote_addr);
+ fprintf(sendmail, "HTTP-Posting-Client: %s\n", Z_STRVAL_PP(remote_addr));
+ }
+ if (zend_hash_find(PG(http_globals)[TRACK_VARS_SERVER]->value.ht, "SERVER_NAME",
sizeof("SERVER_NAME"), (void **) &server_name)==SUCCESS) {
+ convert_to_string_ex(server_name);
+ fprintf(sendmail, "HTTP-Posting-URI: %s", Z_STRVAL_PP(server_name));
+ if (zend_hash_find(PG(http_globals)[TRACK_VARS_SERVER]->value.ht, "SERVER_PORT",
sizeof("SERVER_PORT"), (void **) &server_port)==SUCCESS) {
+ convert_to_string_ex(server_port);
+ fprintf(sendmail, ":%s", Z_STRVAL_PP(server_port));
+ }
+ if (zend_hash_find(PG(http_globals)[TRACK_VARS_SERVER]->value.ht, "SCRIPT_NAME",
sizeof("SCRIPT_NAME"), (void **) &script_name)==SUCCESS) {
+ convert_to_string_ex(script_name);
+ fprintf(sendmail, "%s", Z_STRVAL_PP(script_name));
+ }
+ fprintf(sendmail, "\n");
+ }
+ if (zend_hash_find(PG(http_globals)[TRACK_VARS_SERVER]->value.ht,
"HTTP_USER_AGENT", sizeof("HTTP_USER_AGENT"), (void **)
&http_user_agent)==SUCCESS) {
+ convert_to_string_ex(http_user_agent);
+ fprintf(sendmail, "HTTP-Posting-User-Agent: %s\n", Z_STRVAL_PP(http_user_agent));
+ }
+ }
[I'll add a pointer to this bug report into the mail() user-docs, so that other people can at
least find this more easily.]
------------------------------------------------------------------------
[2012-02-18 05:10:01] php at richardneill dot org
> They aren't documented because we don't add them.
> Your PHP is either patched locally to do this, something else is adding it,
> or you have userspace code doing it.
Thanks for your explanation - this makes sense from PHP's perspective, but it's now really
weird. Googling for these headers shows they are very widespread. I know there is no userspace code
of mine doing this, and I don't think sendmail could be doing it (the MTA can't have
knowledge of the HTTP user-agent).
I'm using the stock PHP build provided by Mageia.
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=61131
--
Edit this bug report at https://bugs.php.net/bug.php?id=61131&edit=1