Re: multiline HTTP headers support in header()
| From: | Ferenc Kovacs | Date: | Thu, 03 Jul 2014 06:14:51 +0000 |
| Subject: | Re: multiline HTTP headers support in header() | ||
| References: | 1 2 3 4 5 6 7 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-75194@lists.php.net to get a copy of this message | ||
On Thu, Jul 3, 2014 at 8:08 AM, Solar Designer <solar@openwall.com> wrote:
> On Thu, Jul 03, 2014 at 07:36:26AM +0200, Ferenc Kovacs wrote:
> > If I'm reading this correctly this would reintroduce
> > https://bugs.php.net/bug.php?id=60227
>
> No.
>
> > those checks aren't there to support header splitting but to prevent
> them,
> > as "\r\n" isn't the only separator which will cause browsers to split the
> > header.
>
> Individual '\r' or '\n' may also separate headers in specific browsers,
> yes. We should continue to disallow them as well.
>
> Adam's patch looks correct to me in this respect: strpbrk() returns
> non-NULL when _any_ of the characters is found.
>
my bad, I blame morning.
--
Ferenc Kovács
@Tyr43l - http://tyrael.hu