Re: Changes in HTTP_xxx_VARS between 4.0.1pl2 and 4.0.3.pl1

From: Date: Thu, 16 Nov 2000 10:13:49 +0000
Subject: Re: Changes in HTTP_xxx_VARS between 4.0.1pl2 and 4.0.3.pl1
Groups: php.general 
Request: Send a blank email to php-general+get-25667@lists.php.net to get a copy of this message
Hi, Yes, I have track_vars enabled - the PHP.INI file was unchanged between the 4.0.1pl2 and 4.0.3pl1 installations. FYI, I've changed the example code slightly, and included the new sample code, output, and an extract of my PHP.INI below. Thanks, Chris. (PS - To summarise the issue, 4.0.1 did not set HTTP_POST_VARS if a GET request was receieved (and vice versa), 4.0.3 sets HTTP_POST_VARS to an empty array when a GET request is received). The script used was: <? if (isset($GLOBALS['HTTP_POST_VARS'])) $http_vars =& $GLOBALS ['HTTP_POST_VARS']; else if (isset($GLOBALS['HTTP_GET_VARS'])) $http_vars =& $GLOBALS ['HTTP_GET_VARS']; else $http_vars = array(); echo '<PRE>'; echo 'POST: '; var_dump($GLOBALS ['HTTP_POST_VARS']); echo 'GET: '; var_dump($GLOBALS ['HTTP_GET_VARS']); echo 'Chosen:'; var_dump($http_vars); echo '</PRE>'; ?> The output (4.0.3) was: (for 'http://quark/http_demo?object=17') POST: array(0) { } GET: array(1) { ["object"]=> string(2) "17" } Chosen:array(0) { } My PHP.INI file is as follows (removing the header and module-specific stuff): ;;;;;;;;;;;;;;;;;;;; ; Language Options ; ;;;;;;;;;;;;;;;;;;;; engine = On ; Enable the PHP scripting language engine under Apache short_open_tag = On ; allow the <? tag. otherwise, only <?php and <script> tags are recognized. asp_tags = Off ; allow ASP-style <% %> tags precision = 14 ; number of significant digits displayed in floating point numbers y2k_compliance = Off ; whether to be year 2000 compliant (will cause problems with non y2k compliant browsers) output_buffering = Off ; Output buffering allows you to send header lines (including cookies) ; even after you send body content, in the price of slowing PHP's ; output layer a bit. ; You can enable output buffering by in runtime by calling the output ; buffering functions, or enable output buffering for all files ; by setting this directive to On. implicit_flush = Off ; Implicit flush tells PHP to tell the output layer to flush itself ; automatically after every output block. This is equivalent to ; calling the PHP function flush() after each and every call to print() ; or echo() and each and every HTML block. ; Turning this option on has serious performance implications, and ; is generally recommended for debugging purposes only. allow_call_time_pass_reference = Off ; whether to enable the ability to force arguments to be ; passed by reference at function-call time. This method ; is deprecated, and is likely to be unsupported in future ; versions of PHP/Zend. The encouraged method of specifying ; which arguments should be passed by reference is in the ; function declaration. You're encouraged to try and ; turn this option Off, and make sure your scripts work ; properly with it, to ensure they will work with future ; versions of the language (you will receive a warning ; each time you use this feature, and the argument will ; be passed by value instead of by reference). ; Safe Mode safe_mode = Off safe_mode_exec_dir = safe_mode_allowed_env_vars = PHP_ ; Setting certain environment variables ; may be a potential security breach. ; This directive contains a comma-delimited ; list of prefixes. In Safe Mode, the ; user may only alter environment ; variables whose names begin with the ; prefixes supplied here. ; By default, users will only be able ; to set environment variables that begin ; with PHP_ (e.g. PHP_FOO=BAR). ; Note: If this directive is empty, PHP ; will let the user modify ANY environment ; variable! safe_mode_protected_env_vars = LD_LIBRARY_PATH ; This directive contains a comma- ; delimited list of environment variables, ; that the end user won't be able to ; change using putenv (). ; These variables will be protected ; even if safe_mode_allowed_env_vars is ; set to allow to change them. disable_functions = ; This directive allows you to disable certain ; functions for security reasons. It receives ; a comma separated list of function names. ; This directive is *NOT* affected by whether ; Safe Mode is turned on or off. ; Colors for Syntax Highlighting mode. Anything that's acceptable in <font color=???> would work. highlight.string = #DD0000 highlight.comment = #FF8000 highlight.keyword = #007700 highlight.bg = #FFFFFF highlight.default = #0000BB highlight.html = #000000 ; Misc expose_php = On ; Decides whether PHP may expose the fact that it is installed on the ; server (e.g., by adding its signature to the Web server header). ; It is no security threat in any way, but it makes it possible ; to determine whether you use PHP on your server or not. zend_optimizer.optimization_level=15 zend_extension="/usr/local/php/lib/ZendOptimizer.so" ;;;;;;;;;;;;;;;;;;; ; Resource Limits ; ;;;;;;;;;;;;;;;;;;; max_execution_time = 30 ; Maximum execution time of each script, in seconds memory_limit = 16777216 ; Maximum amount of memory a script may consume (16 MB) ;;;;;;;;;;;;;;;;;;;;;;;;;;;;;; ; Error handling and logging ; ;;;;;;;;;;;;;;;;;;;;;;;;;;;;;; ; error_reporting is a bit-field. Or each number up to get desired error reporting level ; E_ALL - All errors and warnings ; E_ERROR - fatal run-time errors ; E_WARNING - run-time warnings (non fatal errors) ; E_PARSE - compile-time parse errors ; E_NOTICE - run-time notices (these are warnings which often result from a bug in ; your code, but it's possible that it was intentional (e.g., using an ; uninitialized variable and relying on the fact it's automatically ; initialized to an empty string) ; E_CORE_ERROR - fatal errors that occur during PHP's initial startup ; E_CORE_WARNING - warnings (non fatal errors) that occur during PHP's initial startup ; E_COMPILE_ERROR - fatal compile-time errors ; E_COMPILE_WARNING - compile-time warnings (non fatal errors) ; E_USER_ERROR - user-generated error message ; E_USER_WARNING - user-generated warning message ; E_USER_NOTICE - user-generated notice message ; Examples: ; error_reporting = E_ALL & ~E_NOTICE ; show all errors, except for notices ; error_reporting = E_COMPILE_ERROR|E_ERROR|E_CORE_ERROR ; show only errors error_reporting = E_ALL ; Show all errors except for notices display_errors = On ; Print out errors (as a part of the HTML script) log_errors = On ; Log errors into a log file (server-specific log, stderr, or error_log (below)) track_errors = On ; Store the last error/warning message in $php_errormsg (boolean) error_prepend_string = "<font color=ff0000>" ; string to output before an error message error_append_string = "</font>" ; string to output after an error message error_log = /website/logs/php_error_log ; log errors to specified file ;error_log = syslog ; log errors to syslog (Event Log on NT, not valid in Windows 95) warn_plus_overloading = On ; warn if the + operator is used with strings ;;;;;;;;;;;;;;;;; ; Data Handling ; ;;;;;;;;;;;;;;;;; variables_order = "EGPCS" ; This directive describes the order in which PHP registers ; GET, POST, Cookie, Environment and Built-in variables (G, P, ; C, E & S respectively, often referred to as EGPCS or GPC). ; Registration is done from left to right, newer values override ; older values. register_globals = Off ; Whether or not to register the EGPCS variables as global ; variables. You may want to turn this off if you don't want ; to clutter your scripts' global scope with user data. This makes ; most sense when coupled with track_vars - in which case you can ; access all of the GPC variables through the $HTTP_*_VARS[], ; variables. register_argc_argv = On ; This directive tells PHP whether to declare the argv&argc ; variables (that would contain the GET information). If you ; don't use these variables, you should turn it off for ; increased performance track_vars = On ; enable the $HTTP_*_VARS[] arrays, where * is one of ; ENV, POST, GET, COOKIE or SERVER. gpc_order = "GPC" ; This directive is deprecated. Use variables_order instead. ; Magic quotes magic_quotes_gpc = Off ; magic quotes for incoming GET/POST/Cookie data magic_quotes_runtime= Off ; magic quotes for runtime-generated data, e.g. data from SQL, from exec(), etc. magic_quotes_sybase = Off ; Use Sybase-style magic quotes (escape ' with '' instead of \') ; automatically add files before or after any PHP document auto_prepend_file = auto_append_file = ; As of 4.0b4, PHP always outputs a character encoding by default in ; the Content-type: header. To disable sending of the charset, simply ; set it to be empty. ; PHP's built-in default is text/html default_mimetype = "text/html" ;default_charset = "iso-8859-1" ;;;;;;;;;;;;;;;;;;;;;;;;; ; Paths and Directories ; ;;;;;;;;;;;;;;;;;;;;;;;;; include_path = /website/data/include ; UNIX: "/path1:/path2" Windows: "\path1;\path2" doc_root = ; the root of the php pages, used only if nonempty user_dir = ; the directory under which php opens the script using /~username, used only if nonempty ;upload_tmp_dir = ; temporary directory for HTTP uploaded files (will use system default if not specified) upload_max_filesize = 16777216 ; 16 Meg default limit on file uploads extension_dir = ./ ; directory in which the loadable extensions (modules) reside enable_dl = On ; Whether or not to enable the dl() function. ; The dl() function does NOT properly work in multithreaded ; servers, such as IIS or Zeus, and is automatically disabled ; on them. -----Original Message----- From: Milan Mlynarcik [mailto:mmlynarcik@charmed.sk] Sent: 15 November 2000 19:15 To: cjsmith@btinternet.com Subject: Re: [PHP] Changes in HTTP_xxx_VARS between 4.0.1pl2 and 4.0.3.pl1 And can I ask have you turn on track vars directive in your php.ini file ??? ------------------------------------------------------------- Milan Mlynarcik Web Programmer Charmed Technology Slovakia Nam. sv. Egidia 3633 058 01 Poprad, Slovakia E-mail: mmlynarcik@charmed.sk Office: 00421 92 7881 874 Mobile: 00421 905 964 535 Web page: http://www.charmed.com/ ------------------------------------------------------------- ----- Original Message ----- From: <cjsmith@btinternet.com> To: <php-general@lists.php.net> Sent: Wednesday, November 15, 2000 8:05 PM Subject: [PHP] Changes in HTTP_xxx_VARS between 4.0.1pl2 and 4.0.3.pl1 > Hi, > > I've just upgraded my server from PHP 4.0.1pl2 to > 4.0.3pl1, and most of my pages have broken. This is a > major problem, as I will now have to rewrite EVERY script > on my site that uses this mechanism (which is most of > them), or wind back to 4.0.1. > > Please could someone try to repro this issue, and let > me know the results by email (preferably to > cjs4@gmx.net). > > On 4.0.1, the $GLOBALS['HTTP_POST_VARS'] would only > be set when a POST request was executed. Similarly, > $GLOBALS['HTTP_GET_VARS'] would only be assigned > when a GET request was executed. > > On 4.0.3, $GLOBALS['HTTP_POST_VARS'] becomes is > always assigned as a 0-element array on a GET request. > (I'm assuming similar behaviour for HTTP_GET_VARS on > a POST request). > > Is this intended behaviour, or a transient bug in > 4.0.3pl1? If it is an intended change, why isn't it > mentioned in the ChangeLog? If not, does anyone know > what may have happened to cause this, and how to fix > it? > > The problem can be demonstrated by executing the > following code on each platform: > > <?php > if (isset($GLOBALS['HTTP_POST_VARS'])) > $http_vars =& $GLOBALS['HTTP_POST_VARS']; > else if (isset($GLOBALS['HTTP_GET_VARS'])) > $http_vars =& $GLOBALS['HTTP_GET_VARS']; > else > $http_vars = array(); > > echo '<PRE>'; > var_dump($GLOBALS['HTTP_GET_VARS']); > var_dump($http_vars); > echo '</PRE>'; > ?> > > > TIA, > > Chris. > > -- > PHP General Mailing List (http://www.php.net/) > To unsubscribe, e-mail: php-general- unsubscribe@lists.php.net > For additional commands, e-mail: php-general- help@lists.php.net > To contact the list administrators, e-mail: php-list- admin@lists.php.net

« previous php.general (#25667) next »