Re: multiline HTTP headers support in header()
| From: | Solar Designer | Date: | Thu, 03 Jul 2014 00:50:17 +0000 |
| Subject: | Re: multiline HTTP headers support in header() | ||
| References: | 1 2 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-75182@lists.php.net to get a copy of this message | ||
On Thu, Jul 03, 2014 at 01:40:15AM +0100, Andrea Faulds wrote:
> On 3 Jul 2014, at 01:36, Solar Designer <solar@openwall.com> wrote:
> > Please drop multiline HTTP headers support from PHP header()
>
> Would this be a backwards-compatibility break?
Technically, yes.
In practice, I expect that there are no PHP apps that make use of this
feature.
> We could convert multi-line headers into single-line headers, I suppose, but surely it would
> still break BC?
Yes, and I think it's not a good idea anyway.
Why would header() want to support multiline headers on input to that
PHP function anyway, even with old HTTP RFC that included such support
at HTTP protocol level? I see no valid reason. Was such support
declared anywhere in the documentation, or does it simply happen to be
present in the code as an obscure feature? I guess it's the latter.
> Be that the case, we should probably only do this for PHP 6. Though I wonder if multi-line
> headers are obscure enough, and the security benefits justifiable enough, that we could do it in
> 5.7.
I suggest doing it for 5.4. The new HTTP RFC is already out, so why
keep an undocumented(?) and dangerous misfeature to produce headers that
are already deprecated by the current RFC?
You just need to document the change.
Alexander