Re: header() allows arbitrary status codes

From: Date: Tue, 21 Dec 2021 19:09:35 +0000
Subject: Re: header() allows arbitrary status codes
References: 1  Groups: php.internals 
Request: Send a blank email to internals+get-116708@lists.php.net to get a copy of this message
> > Hi all, > > a while ago it has been reported[1] that our header() function actually > allows arbitrary status codes, which may even overflow. Of course, that > makes no sense, since the status code is supposed to be a three digit > code. So this ticket has been followed up by a pull request[2], and > Jakub suggested to further restrict the status code to be in range 100 - > 599. > > Since this could break some pathological cases, I wanted to ask whether > anybody objects to this change for the master branch (i.e. PHP 8.2). > > [1] <https://bugs.php.net/bug.php?id=81645> > [2] <https://github.com/php/php-src/pull/7676> I think it is a useful improvement. Should we adjust to http_response_code to match this behavior?

« previous php.internals (#116708) next »