Re: HTTP_Request cookies
| From: | Justin Patrin | Date: | Tue, 07 Jun 2005 08:28:51 +0000 |
| Subject: | Re: HTTP_Request cookies | ||
| References: | 1 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-38002@lists.php.net to get a copy of this message | ||
On 6/6/05, Andrei Railean <arailean@squiz.net> wrote:
> Hi All,
> This is my first post to this list, so please don't be too rough.
>
> I've proposed a slight mod to HTTP_Request such that the cookies set
> between redirects are remembered.
> You can see the proposed fix in the bug report:
> http://pear.php.net/bugs/bug.php?id=4505
>
> Currently, if redirects are allowed by HTTP_Request, the redirects will
> happen up to the maximum number allowed. The issue here is that each of
> those redirects can set cookies, which are silently ignored by
> HTTP_Request. This means that the final destination (redirect) might
> not be correct because the intermediate redirects might base their
> redirect header location on the cookies from previous redirects. Since
> so many packages depend on HTTP_Request, I thought that it is important
> to rectify this, even though the multiple redirect scenario with
> cookies might not occur very frequently.
>
> I suspect package maintainers are probably busy so I submitted a
> proposed fix. The fix uses Cookie_Manager - which is a part of
> HTTP_Client package, which depends on HTTP_Request, so that introduces
> a circular reference (somewhat). Don't know the politics of using code
> from child packages used in parent packages, but that suggest that
> Cookie_Manager might need to be independent of HTTP_Client and possibly
> reside under the HTTP root.
>
Well....this is precisely what HTTP_Client is for. To simulate a
normal browser (with regard to cookies and session). HTTP_Request
isn't supposed to have any extra cookie ro session logic. If you move
this from HTTP_Client to HTTP_Request then you might as well just
merge the two packages (which is IMHO a bad idea).
What happens if you use HTTP_Client to make this request? Does it deal
with the cookies ok? If yes, then I suggest you use HTTP_Client for
this (as you should be) and that the HTTP_Request maintainers may want
to add a note to their docs about this type of situation.
--
Justin Patrin