Doc #61893 [Wfx->ReO]: The $_REQUEST Predefined Variable Does NOT Contains the Contents of $_COOKIE
| From: | philip@php.net | Date: | Tue, 28 Aug 2012 18:54:32 +0000 |
| Subject: | Doc #61893 [Wfx->ReO]: The $_REQUEST Predefined Variable Does NOT Contains the Contents of $_COOKIE | ||
| References: | 1 | Groups: | php.doc.bugs |
| Request: | Send a blank email to doc-bugs+get-8784@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=61893&edit=1
ID: 61893
Updated by: philip@php.net
Reported by: marcoscanrib at ig dot com dot br
Summary: The $_REQUEST Predefined Variable Does NOT Contains
the Contents of $_COOKIE
-Status: Wont fix
+Status: Re-Opened
Type: Documentation Problem
Package: Documentation problem
Operating System: Windows XP Prof
PHP Version: 5.3Git-2012-05-02 (Git)
Block user comment: N
Private report: N
New Comment:
The meaning of "default" here is debatable and will never please everyone. But
the request_order documentation shows "" as its default, but does also refer to
the distributed php.ini-* files.
The default value is what PHP would do without a php.ini file. Different
distributions (Linux variants, or packages like the aforementioned XAMPP, and the
like) choose either php.ini-production/php.ini-recommended, or use neither, or
sets custom values, so really the meaning of "default" is unclear. This is why we
use the non-php.ini value as the default. It's simple.
And just to be clear. PHP does not ship with a "php.ini" file as instead one must
manually rename one of the two example files.
But that description is unclear so this bug report now requests that:
A) This be rewritten "Note that the default distribution php.ini files does not
contain the 'C' for cookies, due to security concerns." as it's strange.
B) We have a FAQ entry about what a "default" value means. One that is more
descriptive than our current docs on the matter. It should refer to both php.ini-
* files, that default is non-php.ini, and maybe even mention the -n cli option.
I thought we already did something like (B) but I cannot find.
Previous Comments:
------------------------------------------------------------------------
[2012-08-28 14:23:47] kim dot rowan at cancer dot org dot uk
I would also like to see the documentation updated to reflect the accurate circumstances where
$_REQUEST would incorporate $_COOKIE data alongside $_GET and $_POST as it is currently misleading.
------------------------------------------------------------------------
[2012-05-03 02:24:00] marcoscanrib at ig dot com dot br
I have just searched the documentation for the 'request_order' directive and it
clearly states : "Note that the >>default<< distribution php.ini files does not
contain the 'C' for cookies".
So, I believe this proves that, >>by default<<, $_REQUEST does NOT include the
contents of $_COOKIE and that the following statement in the documentation is
wrong and should be fixed : "Description : An associative array that by default
contains the contents of $_GET, $_POST and $_COOKIE."
------------------------------------------------------------------------
[2012-05-03 02:08:36] marcoscanrib at ig dot com dot br
Congratulations for the quick follow up of the users feedbacks.
About your follow up content, I add that I have not used variables_order nor
request_order to change the default behavior of the $_REQUEST array and I got the
results I stated. So, at least in my PHP installation (XAMPP), the default
behavior of the $_REQUEST is NOT to include the contents of $_COOKIE. Is there a
way to check if XAMPP changed the default behaviour of the $_REQUEST array ?
------------------------------------------------------------------------
[2012-05-02 01:22:05] aharvey@php.net
The documentation already states clearly that that's the default behaviour only
and can be changed via variables_order and request_order.
------------------------------------------------------------------------
[2012-05-02 01:11:32] marcoscanrib at ig dot com dot br
Description:
------------
---
From manual page: http://www.php.net/reserved.variables.request#refsect1-
reserved.variables.request-description
---
Test script:
---------------
<?php
// set the cookies
setcookie("CookieName1", 1);
setcookie("CookieName2", "two");
setcookie("CookieName3", "Cookie 3");
?>
// prints the elements of the $_COOKIE array
<pre>
<?php print_r($_COOKIE); ?>
</pre>
// prints the elements of the $_REQUEST array
<pre>
<?php print_r($_REQUEST); ?>
</pre>
Expected result:
----------------
IF the $_REQUEST predefined array contained the contents of the $_COOKIE
predefined array, as stated at
http://docs.php.net/manual/en/reserved.variables.request.php,
the above script
should display :
Array
(
[CookieName1] => 1
[CookieName2] => two
[CookieName3] => Cookie 3
)
Array
(
[CookieName1] => 1
[CookieName2] => two
[CookieName3] => Cookie 3
)
Actual result:
--------------
The above script displays, that clearly demonstrate that $_REQUEST does NOT
contain the contents of $_COOKIE. I consider the real content of the $_REQUEST
array fine, better than if it also included the contents of the $_COOKIE array.
For me, only the documentation is wrong and should be corrected, what is very
easy indeed.
Array
(
[CookieName1] => 1
[CookieName2] => two
[CookieName3] => Cookie 3
)
Array
(
)
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=61893&edit=1