note 63511 deleted from function.header by danbrown

From: Date: Sun, 23 Jan 2011 17:36:03 +0000
Subject: note 63511 deleted from function.header by danbrown
References: 1  Groups: php.notes 
Request: Send a blank email to php-notes+get-176218@lists.php.net to get a copy of this message
Note Submitter: nick dot b at kingstransport dot com dot au ---- Constructing an absolute URL (for redirecting or other purposes) is full of pitfalls. As well as considering the notes at http://www.php.net/manual/en/function.header.php#63006 and http://www.php.net/manual/en/function.header.php#61746 you need to consider this issue, applicable if you use ProxyPass (in apache). Example httpd.conf ... ProxyPass /dir/ http: //10.1.1.1/dir/ ... Member of public ---> Unix/Apache server ---> IIS/PHP server http: //nick.com/ nick.com myphpsvr.nick.com dir/phpinfo.php 20.10.5.1 10.1.1.1 When your script is on the IIS/PHP server, browsing from member of public, you will have script variables <?php // browsing from member of public $_SERVER['HTTP_HOST'] == '10.1.1.6'; $_SERVER['HTTP_X_FORWARDED_HOST'] == 'nick.com'; $_SERVER['SERVER_NAME'] == '10.1.1.6'; ?> However, if you browse internally (like, when testing, http: //myphpsrv.nick.com/dir/phpinfo.php), the variables turn out like this <?php // browsing from internal, direct $_SERVER['HTTP_HOST'] == 'myphpsvr.nick.com'; $_SERVER['SERVER_NAME'] == 'myphpsvr.nick.com'; // no $_SERVER['HTTP_X_FORWARDED_HOST'] ?> The point is, you need to test $_SERVER['HTTP_X_FORWARDED_HOST'] and use that in preference to either $_SERVER['HTTP_HOST'] or $_SERVER['SERVER_NAME']. Nick Bishop. URL's have intentionally been broken up to stop them being clickable.

« previous php.notes (#176218) next »