header() allows arbitrary status codes
| From: | Christoph M. Becker | Date: | Tue, 21 Dec 2021 18:58:54 +0000 |
| Subject: | header() allows arbitrary status codes | ||
| Groups: | php.internals | ||
| Request: | Send a blank email to internals+get-116707@lists.php.net to get a copy of this message | ||
Hi all,
a while ago it has been reported[1] that our header() function actually
allows arbitrary status codes, which may even overflow. Of course, that
makes no sense, since the status code is supposed to be a three digit
code. So this ticket has been followed up by a pull request[2], and
Jakub suggested to further restrict the status code to be in range 100 -
599.
Since this could break some pathological cases, I wanted to ask whether
anybody objects to this change for the master branch (i.e. PHP 8.2).
[1] <https://bugs.php.net/bug.php?id=81645>
[2] <https://github.com/php/php-src/pull/7676>
Christoph