#22338 [Asn->Ana]: XML-RPC classes rely on $HTTP_RAW_POST_DATA

From: Date: Thu, 31 Jul 2003 08:53:01 +0000
Subject: #22338 [Asn->Ana]: XML-RPC classes rely on $HTTP_RAW_POST_DATA
References: 1  Groups: php.pear.dev 
Request: Send a blank email to pear-dev+get-19006@lists.php.net to get a copy of this message
ID: 22338 Updated by: nicos@php.net Reported By: stuart at gnqs dot org -Status: Assigned +Status: Analyzed Bug Type: PEAR related Operating System: Windows XP PHP Version: 4.3.0 Assigned To: ssb New Comment: According to bertrand, here is a patch for that. I need feedback from the maintainer before commiting it. Index: Server.php =================================================================== RCS file: /repository/pear/XML_RPC/Server.php,v retrieving revision 1.2 diff -u -u -r1.2 Server.php --- Server.php 28 Feb 2002 10:59:30 -0000 1.2 +++ Server.php 31 Jul 2003 08:52:13 -0000 @@ -221,8 +221,13 @@ global $XML_RPC_err, $XML_RPC_str, $XML_RPC_errxml, $XML_RPC_defencoding, $XML_RPC_Server_dmap; - if ($data=="") { - $data=$HTTP_RAW_POST_DATA; + if (isset($HTTP_RAW_POST_DATA)) { + $input = $HTTP_RAW_POST_DATA; + } else { + $input = implode("\r\n", file('php://input')); + } + if (empty($data)) { + $data = $input; } $parser = xml_parser_create($XML_RPC_defencoding); @@ -301,9 +306,13 @@ // a debugging routine: just echos back the input // packet as a string value - + if (isset($HTTP_RAW_POST_DATA)) { + $input = $HTTP_RAW_POST_DATA; + } else { + $input = implode("\r\n", file('php://input')); + } $r=new XML_RPC_Response; - $r->xv=new XML_RPC_Value( "'Aha said I: '" . $HTTP_RAW_POST_DATA, "string"); + $r->xv=new XML_RPC_Value( "'Aha said I: '" . $input, "string"); print $r->serialize(); } } Previous Comments: ------------------------------------------------------------------------ [2003-04-27 09:55:17] philip@php.net This is not affected by register_globals and if it is then that's a bug in itself, it would have been a very recent change and a BC issue. Are you saying it's defined with register_globals on and undefined when off, with this being the ONLY change?!! I sincerly hope this isn't the case although if register_globals decides to register it even when no value exists that wouldn't be a _major_ deal, just silly. Regarding php://input, this also has issues as AFAICT it didn't work for this with CGI before PHP 4.3.0. The existence of this raw post information is pretty sketchy in PHP, I don't envy anyone writing scripts that rely on it. Here's a quote from Hartmut who was working on fixing it (quoted from the above thread): "from now on i declare it best practice to use php://input for 4.3 while $HTTP_RAW_POST_DATA is still available for BC reasons ... :)" And lastly, the existence of this variable shouldn't rely on any directive as it's creation can be forced (bad mime...). That always populate directive just makes it easier to deal with. In conclusion, I believe a hack is required to check for and find this information in both locations. ------------------------------------------------------------------------ [2003-04-27 04:56:50] mansion@php.net I agree with that, the best way is to use php://input when $HTTP_RAW_POST_DATA is not set. This is how it's done in horde [1] and in a few other applications. IMO, this should be changed in XMLRPC package but I don't know who is the maintainer of this package. [1] http://cvs.horde.org/co.php/horde/rpc.php?r=1.14 ------------------------------------------------------------------------ [2003-04-27 04:20:48] stuart at gnqs dot org Hi Philip, A simple one-liner proves that $HTTP_RAW_POST_DATA doesn't exist when register_globals=off <?php echo $HTTP_RAW_POST_DATA ?> On my PHP installation, that generates the error: Notice: Undefined variable: HTTP_RAW_POST_DATA in c:\devel\htdocs\test.php on line 3 I'd never heard of a 'always_populate_raw_post_data' directive. Wouldn't it be better to make the code work without having to set specific directives in php.ini files (not everyone has permissions to do this, y'know)? If you use the php://input stream to get the data instead, this will work in every installation. Best regards, Stu -- ------------------------------------------------------------------------ [2003-04-26 18:21:01] philip@php.net Actually, this variable is not affected by register_globals, it doesn't live in any superglobal. It's its own variable. AFAICT its created when either an unrecognized mime type is provided and/or the php directive always_populate_raw_post_data = on. I tried to grasp it once but gave up, here are the related threads: http://marc.theaimsgroup.com/?l=php-dev&m=103688014620968 http://marc.theaimsgroup.com/?l=php-dev&m=103709898507271 Maybe someone with a better understanding of HTTP can make sense of all this, sorry to get a little offtopic. ------------------------------------------------------------------------ [2003-02-20 15:19:23] stuart at gnqs dot org Hi, Just been looking at the XML-RPC classes in PEAR. Granted, I haven't tried running the code, but from inspection it appears to rely on $HTTP_RAW_POST_DATA. That particular variable doesn't exist if register_globals is set to 'off'. The php://input stream has been around since PHP 3.x (according to the manual), and might be a more portable way of handling this. Just tested this under PHP 4.3.0 with register_globals off, and (as expected) it worked fine. Do any other classes in PEAR rely on $HTTP_RAW_POST_DATA? Best regards, Stu -- ------------------------------------------------------------------------ -- Edit this bug report at http://bugs.php.net/?id=22338&edit=1

« previous php.pear.dev (#19006) next »