note 124276 deleted from function.setcookie by crell
| From: | crell@php.net | Date: | Tue, 12 Apr 2022 00:37:16 +0000 |
| Subject: | note 124276 deleted from function.setcookie by crell | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-218153@lists.php.net to get a copy of this message | ||
Note Submitter: niall at maranelda dot org
----
Be warned! PHP will mangle the names of incoming cookies far more than others have detailed below!
Theoretically, the following non-alphanumeric characters are allowed in a cookie name:
!#$%&'()*+-./:<>?@[]^_`{|}~
However, if you do this:
<?php
setcookie('!#$%&\'()*+-./:<>?@[]^_`{|}~', 123);
setcookie('!#$%&\'()*+-./:<>?@[^_`{|}~', 466);
setcookie('!#$%&\'()*+-./:<>?@]^_`{|}~', 789);
setcookie('!#$%&\'()*+-./:<>?@^_`{|}~', 'abc');
?>
then this:
<?php
print_r($_COOKIE);
?>
you get this back:
<?php
Array
(
[!#$%&'()*_-_/:<>?@] => Array
(
[0] => 123
)
[!#$%&'()*_-_/:<>?@_^_`{|}~] => 456
[!#$%&'()*_-_/:<>?@]^_`{|}~] => 789
[!#$%&'()*_-_/:<>?@^_`{|}~] => abc
)
?>
The rules would appear to be as follows:
- Convert all periods to underscores (as detailed below).
- Convert all plus signs to underscores.
- Convert all unmatched open square brackets to underscores.
- Square bracket pairs mean the value is an array; ignore everything after the closing square
bracket.
Note that these rules are only applied by PHP when generating the $_COOKIE array; the cookie name
part in the headers sent by your browser and as received by PHP are exactly as you specified above;
<?php
echo $_SERVER['HTTP_COOKIE'];
?>
gives
<?php
!#$%&'()*+-./:<>?@[]^_
{|}~=123;
!#$%&'()*+-./:<>?@[^_{|}~=456;
!#$%&'()*+-./:<>?@]^_{|}~=789;
!#$%&'()*+-./:<>?@^_{|}~=abc
?>
It would be nice if the official notes mentioned this conversion.