Re: multiline HTTP headers support in header()
| From: | Adam Harvey | Date: | Thu, 03 Jul 2014 17:37:41 +0000 |
| Subject: | Re: multiline HTTP headers support in header() | ||
| References: | 1 2 3 4 5 6 7 8 9 10 11 12 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-75235@lists.php.net to get a copy of this message | ||
On 3 July 2014 03:11, Tjerk Meesters <tjerk.meesters@gmail.com> wrote:
>
> On Thu, Jul 3, 2014 at 4:24 PM, Stas Malyshev <smalyshev@sugarcrm.com>
> wrote:
>>
>> Hi!
>>
>> > Or, check for NUL byte first and reject the whole thing if present; then
>> > continue with
strpbrk() :)
>>
>> To check for nul, you need to scan the whole string. If you're already
>> doing this, you don't need strpbrk anymore.
>
>
> Right, with that in mind we might as well keep the current loop and just
> break at those three "bad" characters :)
I've updated https://github.com/LawnGnome/php-src/compare/remove-multiline-headers?expand=1
to do just that. I also added a null byte test to the new
header_multiline.phpt test — I don't see a case in the bug60227 tests
that I'm removing that isn't now covered (all the other tests there
were related to multiline support, which has now been removed, so
there's little point retaining those tests).
I'm still thinking master and possibly 5.6 only for this. Does anyone
else have any thoughts (particularly Ferenc and/or Julien on the 5.6
front)?
Adam