Re: multiline HTTP headers support in header()
| From: | Adam Harvey | Date: | Thu, 03 Jul 2014 18:13:43 +0000 |
| Subject: | Re: multiline HTTP headers support in header() | ||
| References: | 1 2 3 4 5 6 7 8 9 10 11 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-75239@lists.php.net to get a copy of this message | ||
On 3 July 2014 11:02, Solar Designer <solar@openwall.com> wrote:
> On Thu, Jul 03, 2014 at 10:56:03AM -0700, Adam Harvey wrote:
>> On 3 July 2014 10:54, Solar Designer <solar@openwall.com> wrote:
>> > On Thu, Jul 03, 2014 at 10:37:41AM -0700, Adam Harvey wrote:
>> >> I've updated
>> >> https://github.com/LawnGnome/php-src/compare/remove-multiline-headers?expand=1
>> >> to do just that. I also added a null byte test to the new
>> >> header_multiline.phpt test ??? I don't see a case in the bug60227 tests
>> >> that I'm removing that isn't now covered (all the other tests there
>> >> were related to multiline support, which has now been removed, so
>> >> there's little point retaining those tests).
>> >
>> > It could make sense to keep the multiline header tests, with the new
>> > expected results, to make sure they'll fail if the support somehow gets
>> > reintroduced. %-)
>
> ... and here's how this may get reintroduced: if someone upgrades their
> PHP source tree by applying a patch, and a relevant hunk fails to apply.
> Then if the tests are nevertheless updated, they'll catch that.
I'm struggling to imagine that happening in a Git world, but sure.
>> Fair, but that _is_ covered by the new test. :)
>
> I don't see it among your tests currently at the URL above. You have
> tests for multiple headers in one header() call, but not for multiline
> headers. In other words, you're no longer testing what happens in the
> special case when a CR or/and LF is followed by a space or TAB.
I don't think it's terribly useful to do so, but I've added those
scenarios to the test.
Adam, who is apparently insufficiently paranoid.