Re: Disallow newlines in CURLOPT_HTTPHEADER
| From: | Matteo Beccati | Date: | Thu, 09 Jul 2026 11:23:58 +0000 |
| Subject: | Re: Disallow newlines in CURLOPT_HTTPHEADER | ||
| References: | 1 2 3 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-131836@lists.php.net to get a copy of this message | ||
Hi Tim,
Il 09/07/2026 13:10, Tim Düsterhus ha scritto:
Hi On 2026-07-09 12:49, Matteo Beccati wrote:Yes, that's precisely my point. "\r\n" followed by a space or tab used to be a thing. Yes, it is obsolete, but for whatever reason I might be required to test that specific scenario using curl."\r\n" inside headers used to be perfectly legal for multiline headers.This is not correct. What was legal was the sequence "\r\n" followed *by either a space or a tab*. And it is equivalent to just a space. The newlines are not “visible” in the parsed value. There is literally zero reason to emit the obsolete line-folding syntax nowadays. As far as I can tell it only existed due to considerations regarding the length of a single line.
Curl specifically documents:Blocking "\r\n" would be perfectly fine in a userland HTTP Client before calling curl_setopt(). Cheers -- Matteo BeccatiThe headers included in the linked list must not be CRLF-terminated, since libcurl adds CRLF after each header item itself. Failure to comply with this might result in strange behavior. libcurl passes on the verbatim strings you give it, without any filter or other safe guards. That includes white space and control characters. Yes, and that seems to be a design choice from the curl team, that we might want to respect.