Doc #61893 [Wfx->ReO]: The $_REQUEST Predefined Variable Does NOT Contains the Contents of $_COOKIE

From: Date: Tue, 28 Aug 2012 18:54:32 +0000
Subject: Doc #61893 [Wfx->ReO]: The $_REQUEST Predefined Variable Does NOT Contains the Contents of $_COOKIE
References: 1  Groups: php.doc.bugs 
Request: Send a blank email to doc-bugs+get-8784@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=61893&edit=1 ID: 61893 Updated by: philip@php.net Reported by: marcoscanrib at ig dot com dot br Summary: The $_REQUEST Predefined Variable Does NOT Contains the Contents of $_COOKIE -Status: Wont fix +Status: Re-Opened Type: Documentation Problem Package: Documentation problem Operating System: Windows XP Prof PHP Version: 5.3Git-2012-05-02 (Git) Block user comment: N Private report: N New Comment: The meaning of "default" here is debatable and will never please everyone. But the request_order documentation shows "" as its default, but does also refer to the distributed php.ini-* files. The default value is what PHP would do without a php.ini file. Different distributions (Linux variants, or packages like the aforementioned XAMPP, and the like) choose either php.ini-production/php.ini-recommended, or use neither, or sets custom values, so really the meaning of "default" is unclear. This is why we use the non-php.ini value as the default. It's simple. And just to be clear. PHP does not ship with a "php.ini" file as instead one must manually rename one of the two example files. But that description is unclear so this bug report now requests that: A) This be rewritten "Note that the default distribution php.ini files does not contain the 'C' for cookies, due to security concerns." as it's strange. B) We have a FAQ entry about what a "default" value means. One that is more descriptive than our current docs on the matter. It should refer to both php.ini- * files, that default is non-php.ini, and maybe even mention the -n cli option. I thought we already did something like (B) but I cannot find. Previous Comments: ------------------------------------------------------------------------ [2012-08-28 14:23:47] kim dot rowan at cancer dot org dot uk I would also like to see the documentation updated to reflect the accurate circumstances where $_REQUEST would incorporate $_COOKIE data alongside $_GET and $_POST as it is currently misleading. ------------------------------------------------------------------------ [2012-05-03 02:24:00] marcoscanrib at ig dot com dot br I have just searched the documentation for the 'request_order' directive and it clearly states : "Note that the >>default<< distribution php.ini files does not contain the 'C' for cookies". So, I believe this proves that, >>by default<<, $_REQUEST does NOT include the contents of $_COOKIE and that the following statement in the documentation is wrong and should be fixed : "Description : An associative array that by default contains the contents of $_GET, $_POST and $_COOKIE." ------------------------------------------------------------------------ [2012-05-03 02:08:36] marcoscanrib at ig dot com dot br Congratulations for the quick follow up of the users feedbacks. About your follow up content, I add that I have not used variables_order nor request_order to change the default behavior of the $_REQUEST array and I got the results I stated. So, at least in my PHP installation (XAMPP), the default behavior of the $_REQUEST is NOT to include the contents of $_COOKIE. Is there a way to check if XAMPP changed the default behaviour of the $_REQUEST array ? ------------------------------------------------------------------------ [2012-05-02 01:22:05] aharvey@php.net The documentation already states clearly that that's the default behaviour only and can be changed via variables_order and request_order. ------------------------------------------------------------------------ [2012-05-02 01:11:32] marcoscanrib at ig dot com dot br Description: ------------ --- From manual page: http://www.php.net/reserved.variables.request#refsect1- reserved.variables.request-description --- Test script: --------------- <?php // set the cookies setcookie("CookieName1", 1); setcookie("CookieName2", "two"); setcookie("CookieName3", "Cookie 3"); ?> // prints the elements of the $_COOKIE array <pre> <?php print_r($_COOKIE); ?> </pre> // prints the elements of the $_REQUEST array <pre> <?php print_r($_REQUEST); ?> </pre> Expected result: ---------------- IF the $_REQUEST predefined array contained the contents of the $_COOKIE predefined array, as stated at http://docs.php.net/manual/en/reserved.variables.request.php, the above script should display : Array ( [CookieName1] => 1 [CookieName2] => two [CookieName3] => Cookie 3 ) Array ( [CookieName1] => 1 [CookieName2] => two [CookieName3] => Cookie 3 ) Actual result: -------------- The above script displays, that clearly demonstrate that $_REQUEST does NOT contain the contents of $_COOKIE. I consider the real content of the $_REQUEST array fine, better than if it also included the contents of the $_COOKIE array. For me, only the documentation is wrong and should be corrected, what is very easy indeed. Array ( [CookieName1] => 1 [CookieName2] => two [CookieName3] => Cookie 3 ) Array ( ) ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=61893&edit=1

« previous php.doc.bugs (#8784) next »