Decoding cookie names

From: Date: Mon, 21 Sep 2020 01:22:24 +0000
Subject: Decoding cookie names
Groups: php.internals 
Request: Send a blank email to internals+get-111908@lists.php.net to get a copy of this message
Hi! In one of the bug reports there was a question raised - should PHP be decoding cookie names? Right now it does. The standard is pretty much silent on this, and looks like such behavior leads to security problems: https://hackerone.com/reports/895727 However I am not sure whether it's ok to change it, since it fails a couple of tests (easy to fix) and may also break some stuff I have no idea about. In general, using url-encoded cookie names is very weird, but I can't guarantee nobody does it. So, I wonder what exactly should we do in this case? RoR folks just changed the code to not decode cookies. Also, php_setcookie() does not seem to encode cookie names (note: we're talking names not values here!) when we send them out, so maybe it doesn't make sense to decode them when we receive them? What do you think? -- Stas Malyshev smalyshev@gmail.com

« previous php.internals (#111908) next »