Re: multiline HTTP headers support in header()

From: Date: Thu, 03 Jul 2014 06:14:51 +0000
Subject: Re: multiline HTTP headers support in header()
References: 1 2 3 4 5 6 7  Groups: php.internals 
Request: Send a blank email to internals+get-75194@lists.php.net to get a copy of this message
On Thu, Jul 3, 2014 at 8:08 AM, Solar Designer <solar@openwall.com> wrote: > On Thu, Jul 03, 2014 at 07:36:26AM +0200, Ferenc Kovacs wrote: > > If I'm reading this correctly this would reintroduce > > https://bugs.php.net/bug.php?id=60227 > > No. > > > those checks aren't there to support header splitting but to prevent > them, > > as "\r\n" isn't the only separator which will cause browsers to split the > > header. > > Individual '\r' or '\n' may also separate headers in specific browsers, > yes. We should continue to disallow them as well. > > Adam's patch looks correct to me in this respect: strpbrk() returns > non-NULL when _any_ of the characters is found. > my bad, I blame morning. -- Ferenc Kovács @Tyr43l - http://tyrael.hu

« previous php.internals (#75194) next »