Re: multiline HTTP headers support in header()

From: Date: Thu, 03 Jul 2014 06:08:37 +0000
Subject: Re: multiline HTTP headers support in header()
References: 1 2 3 4 5 6  Groups: php.internals 
Request: Send a blank email to internals+get-75192@lists.php.net to get a copy of this message
On Thu, Jul 03, 2014 at 07:36:26AM +0200, Ferenc Kovacs wrote: > If I'm reading this correctly this would reintroduce > https://bugs.php.net/bug.php?id=60227 No. > those checks aren't there to support header splitting but to prevent them, > as "\r\n" isn't the only separator which will cause browsers to split the > header. Individual '\r' or '\n' may also separate headers in specific browsers, yes. We should continue to disallow them as well. Adam's patch looks correct to me in this respect: strpbrk() returns non-NULL when _any_ of the characters is found. Why did the old code special-case NUL, though? Should we possibly preserve that? Alexander

« previous php.internals (#75192) next »