Re: multiline HTTP headers support in header()
| From: | Solar Designer | Date: | Thu, 03 Jul 2014 06:05:12 +0000 |
| Subject: | Re: multiline HTTP headers support in header() | ||
| References: | 1 2 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-75191@lists.php.net to get a copy of this message | ||
On Thu, Jul 03, 2014 at 07:33:49AM +0200, Ferenc Kovacs wrote:
> maybe I'm missing something here,
I guess so.
> but we don't really "support" multiline
> headers with header() anymore since 5.1.2,
If you mean bug 60227, then you're confusing things here. That bug was
about having multiple headers sent by header(). I am talking about
individual multiline headers.
> but from time to time this issue
> resurfaces, mostly because some browsers split header lines on other
> characters (https://bugs.php.net/bug.php?id=60227 and
>
> http://lab.onsec.ru/2012/08/php-multiple-headers-bypass-available.html)
> than we originally assumed or what the RFC 2616 allows.
> so I'm not sure how could we fix this other than a one-by-one basis when we
> find another browser quirk like this.
I've seen bug 60227 before. We shouldn't reintroduce that bug, but we
should drop support for multiline headers. There's no contradiction.
Alexander