Re: multiline HTTP headers support in header()

From: Date: Thu, 03 Jul 2014 06:05:12 +0000
Subject: Re: multiline HTTP headers support in header()
References: 1 2  Groups: php.internals 
Request: Send a blank email to internals+get-75191@lists.php.net to get a copy of this message
On Thu, Jul 03, 2014 at 07:33:49AM +0200, Ferenc Kovacs wrote: > maybe I'm missing something here, I guess so. > but we don't really "support" multiline > headers with header() anymore since 5.1.2, If you mean bug 60227, then you're confusing things here. That bug was about having multiple headers sent by header(). I am talking about individual multiline headers. > but from time to time this issue > resurfaces, mostly because some browsers split header lines on other > characters (https://bugs.php.net/bug.php?id=60227 and > > http://lab.onsec.ru/2012/08/php-multiple-headers-bypass-available.html) > than we originally assumed or what the RFC 2616 allows. > so I'm not sure how could we fix this other than a one-by-one basis when we > find another browser quirk like this. I've seen bug 60227 before. We shouldn't reintroduce that bug, but we should drop support for multiline headers. There's no contradiction. Alexander

« previous php.internals (#75191) next »