Decoding cookie names
| From: | Stanislav Malyshev | Date: | Mon, 21 Sep 2020 01:22:24 +0000 |
| Subject: | Decoding cookie names | ||
| Groups: | php.internals | ||
| Request: | Send a blank email to internals+get-111908@lists.php.net to get a copy of this message | ||
Hi!
In one of the bug reports there was a question raised - should PHP be decoding cookie names? Right now it does. The standard is pretty much silent on this, and looks like such behavior leads to security problems: https://hackerone.com/reports/895727
However I am not sure whether it's ok to change it, since it fails a couple of tests (easy to fix) and may also break some stuff I have no idea about. In general, using url-encoded cookie names is very weird, but I can't guarantee nobody does it. So, I wonder what exactly should we do in this case?
RoR folks just changed the code to not decode cookies.
Also, php_setcookie() does not seem to encode cookie names (note: we're talking names not values here!) when we send them out, so maybe it doesn't make sense to decode them when we receive them?
What do you think?
--
Stas Malyshev
smalyshev@gmail.com