Re: multiline HTTP headers support in header()
| From: | Solar Designer | Date: | Thu, 03 Jul 2014 06:08:37 +0000 |
| Subject: | Re: multiline HTTP headers support in header() | ||
| References: | 1 2 3 4 5 6 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-75192@lists.php.net to get a copy of this message | ||
On Thu, Jul 03, 2014 at 07:36:26AM +0200, Ferenc Kovacs wrote:
> If I'm reading this correctly this would reintroduce
> https://bugs.php.net/bug.php?id=60227
No.
> those checks aren't there to support header splitting but to prevent them,
> as "\r\n" isn't the only separator which will cause browsers to split the
> header.
Individual '\r' or '\n' may also separate headers in specific browsers,
yes. We should continue to disallow them as well.
Adam's patch looks correct to me in this respect: strpbrk() returns
non-NULL when _any_ of the characters is found.
Why did the old code special-case NUL, though? Should we possibly
preserve that?
Alexander