Re: multiline HTTP headers support in header()

From: Date: Thu, 03 Jul 2014 00:50:17 +0000
Subject: Re: multiline HTTP headers support in header()
References: 1 2  Groups: php.internals 
Request: Send a blank email to internals+get-75182@lists.php.net to get a copy of this message
On Thu, Jul 03, 2014 at 01:40:15AM +0100, Andrea Faulds wrote: > On 3 Jul 2014, at 01:36, Solar Designer <solar@openwall.com> wrote: > > Please drop multiline HTTP headers support from PHP header() > > Would this be a backwards-compatibility break? Technically, yes. In practice, I expect that there are no PHP apps that make use of this feature. > We could convert multi-line headers into single-line headers, I suppose, but surely it would > still break BC? Yes, and I think it's not a good idea anyway. Why would header() want to support multiline headers on input to that PHP function anyway, even with old HTTP RFC that included such support at HTTP protocol level? I see no valid reason. Was such support declared anywhere in the documentation, or does it simply happen to be present in the code as an obscure feature? I guess it's the latter. > Be that the case, we should probably only do this for PHP 6. Though I wonder if multi-line > headers are obscure enough, and the security benefits justifiable enough, that we could do it in > 5.7. I suggest doing it for 5.4. The new HTTP RFC is already out, so why keep an undocumented(?) and dangerous misfeature to produce headers that are already deprecated by the current RFC? You just need to document the change. Alexander

« previous php.internals (#75182) next »