note 63511 added to function.header

From: Date: Thu, 23 Mar 2006 02:57:02 +0000
Subject: note 63511 added to function.header
Groups: php.notes 
Request: Send a blank email to php-notes+get-106411@lists.php.net to get a copy of this message
Constructing an absolute URL (for redirecting or other purposes) is full of pitfalls. As well as considering the notes at http://www.php.net/manual/en/function.header.php#63006 and http://www.php.net/manual/en/function.header.php#61746 you need to consider this issue, applicable if you use ProxyPass (in apache). Example httpd.conf ... ProxyPass /dir/ http: //10.1.1.1/dir/ ... Member of public ---> Unix/Apache server ---> IIS/PHP server http: //nick.com/ nick.com myphpsvr.nick.com dir/phpinfo.php 20.10.5.1 10.1.1.1 When your script is on the IIS/PHP server, browsing from member of public, you will have script variables <?php // browsing from member of public $_SERVER['HTTP_HOST'] == '10.1.1.6'; $_SERVER['HTTP_X_FORWARDED_HOST'] == 'nick.com'; $_SERVER['SERVER_NAME'] == '10.1.1.6'; ?> However, if you browse internally (like, when testing, http: //myphpsrv.nick.com/dir/phpinfo.php), the variables turn out like this <?php // browsing from internal, direct $_SERVER['HTTP_HOST'] == 'myphpsvr.nick.com'; $_SERVER['SERVER_NAME'] == 'myphpsvr.nick.com'; // no $_SERVER['HTTP_X_FORWARDED_HOST'] ?> The point is, you need to test $_SERVER['HTTP_X_FORWARDED_HOST'] and use that in preference to either $_SERVER['HTTP_HOST'] or $_SERVER['SERVER_NAME']. Nick Bishop. URL's have intentionally been broken up to stop them being clickable. ---- Server IP: 66.163.161.117 Probable Submitter: 61.29.13.192 ---- X-Spam-Status: No, hits=3.8 required=5.0 tests=DATE_MISSING,FROM_NO_LOWER, UPPERCASE_25_50 autolearn=no version=2.64 ---- Manual Page -- http://www.php.net/manual/en/function.header.php Edit -- http://master.php.net/note/edit/63511 Del: integrated -- http://master.php.net/note/delete/63511/integrated Del: useless -- http://master.php.net/note/delete/63511/useless Del: bad code -- http://master.php.net/note/delete/63511/bad+code Del: spam -- http://master.php.net/note/delete/63511/spam Del: non-english -- http://master.php.net/note/delete/63511/non-english Del: in docs -- http://master.php.net/note/delete/63511/in+docs Del: other reasons-- http://master.php.net/note/delete/63511 Reject -- http://master.php.net/note/reject/63511 Search -- http://master.php.net/manage/user-notes.php

« previous php.notes (#106411) next »