note 118967 added to function.curl-setopt
| From: | joey | Date: | Wed, 09 Mar 2016 18:54:57 +0000 |
| Subject: | note 118967 added to function.curl-setopt | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-205122@lists.php.net to get a copy of this message | ||
It is important that anyone working with cURL and PHP keep in mind that not all of the CURLOPT and
CURLINFO constants are documented. I always recommend reading the cURL documentation directly as it
sometimes contains better information. The cURL API in tends to be fubar as well so do not expect
things to be where you would normally logically look for them.
curl is especially difficult to work with when it comes to cookies. So I will talk about what I
found with PHP 5.6 and curl 7.26.
If you want to manage cookies in memory without using files including reading, writing and clearing
custom cookies then continue reading.
To start with, the way to enable in memory only cookies associated with a cURL handle you should
use:
curl_setopt($curl, CURLOPT_COOKIEFILE, "");
cURL likes to use magic strings in options as special commands. Rather than having an option to
enable the cookie engine in memory it uses a magic string to do that. Although vaguely the
documentation here mentions this however most people like me wouldn't even read that because a
COOKIEFILE is the complete opposite of what we want.
To get the cookies for a curl handle you can use:
curl_getinfo($curl, CURLINFO_COOKIELIST);
This will give an array containing a string for each cookie. It is tab delimited and unfortunately
you will have to parse it yourself if you want to do anything beyond copying the cookies.
To clear the in memory cookies for a cURL handle you can use:
curl_setopt($curl, CURLOPT_COOKIELIST, "ALL");
This is a magic string. There are others in the cURL documentation. If a magic string isn't
used, this field should take a cookie in the same string format as in getinfo for the cookielist
constant. This can be used to delete individual cookies although it's not the most elegant API
for doing so.
For copying cookies I recommend using curl_share_init.
You can also copy cookies from one handle to another like so:
foreach(curl_getinfo($curl_a, CURLINFO_COOKIELIST) as $cookie_line)
curl_setopt($curl, CURLOPT_COOKIELIST, $cookie_line);
An inelegant way to delete a cookie would be to skip the one you don't want.
I only recommend using COOKIELIST with magic strings because the cookie format is not secure or
stable. You can inject tabs into at least path and name so it becomes impossible to parse reliably.
If you must parse this then to keep it secure I recommend prohibiting more than 6 tabs in the
content which probably isn't a big loss to most people.
A the absolute minimum for validation I would suggest:
/^([^\t]+\t){5}[^\t]+$/D
Here is the format:
#define SEP "\t" /* Tab separates the fields */
char *my_cookie =
"example.com" /* Hostname */
SEP "FALSE" /* Include subdomains */
SEP "/" /* Path */
SEP "FALSE" /* Secure */
SEP "0" /* Expiry in epoch time format. 0 == Session */
SEP "foo" /* Name */
SEP "bar"; /* Value */
----
Server IP: 72.52.91.14
Probable Submitter: 149.6.187.130
----
Manual Page -- http://php.net/manual/en/function.curl-setopt.php
Edit -- https://master.php.net/note/edit/118967
Del: integrated -- https://master.php.net/note/delete/118967/integrated
Del: useless -- https://master.php.net/note/delete/118967/useless
Del: bad code -- https://master.php.net/note/delete/118967/bad+code
Del: spam -- https://master.php.net/note/delete/118967/spam
Del: non-english -- https://master.php.net/note/delete/118967/non-english
Del: in docs -- https://master.php.net/note/delete/118967/in+docs
Del: other reasons-- https://master.php.net/note/delete/118967
Reject -- https://master.php.net/note/reject/118967
Search -- https://master.php.net/manage/user-notes.php