Skip to content

Commit 3c3b2b5

Browse files
committed
Handle CLI server request headers case insensitively.
Fixes bug #65633 (built-in server treat some http headers as case-sensitive).
1 parent 7beef74 commit 3c3b2b5

File tree

3 files changed

+59
-10
lines changed

3 files changed

+59
-10
lines changed

NEWS

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -2,6 +2,10 @@ PHP NEWS
22
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
33
?? ??? 2013, PHP 5.4.21
44

5+
- CLI server:
6+
. Fixed bug #65633 (built-in server treat some http headers as
7+
case-sensitive). (Adam)
8+
59
?? ??? 2013, PHP 5.4.20
610

711
- Core:

sapi/cli/php_cli_server.c

Lines changed: 7 additions & 10 deletions
Original file line numberDiff line numberDiff line change
@@ -408,7 +408,7 @@ static void append_essential_headers(smart_str* buffer, php_cli_server_client *c
408408
{
409409
{
410410
char **val;
411-
if (SUCCESS == zend_hash_find(&client->request.headers, "Host", sizeof("Host"), (void**)&val)) {
411+
if (SUCCESS == zend_hash_find(&client->request.headers, "host", sizeof("host"), (void**)&val)) {
412412
smart_str_appendl_ex(buffer, "Host", sizeof("Host") - 1, persistent);
413413
smart_str_appendl_ex(buffer, ": ", sizeof(": ") - 1, persistent);
414414
smart_str_appends_ex(buffer, *val, persistent);
@@ -558,7 +558,7 @@ static char *sapi_cli_server_read_cookies(TSRMLS_D) /* {{{ */
558558
{
559559
php_cli_server_client *client = SG(server_context);
560560
char **val;
561-
if (FAILURE == zend_hash_find(&client->request.headers, "Cookie", sizeof("Cookie"), (void**)&val)) {
561+
if (FAILURE == zend_hash_find(&client->request.headers, "cookie", sizeof("cookie"), (void**)&val)) {
562562
return NULL;
563563
}
564564
return *val;
@@ -1556,12 +1556,9 @@ static int php_cli_server_client_read_request_on_header_value(php_http_parser *p
15561556
return 1;
15571557
}
15581558
{
1559-
char *header_name = client->current_header_name;
1560-
size_t header_name_len = client->current_header_name_len;
1561-
char c = header_name[header_name_len];
1562-
header_name[header_name_len] = '\0';
1563-
zend_hash_add(&client->request.headers, header_name, header_name_len + 1, &value, sizeof(char *), NULL);
1564-
header_name[header_name_len] = c;
1559+
char *header_name = zend_str_tolower_dup(client->current_header_name, client->current_header_name_len);
1560+
zend_hash_add(&client->request.headers, header_name, client->current_header_name_len + 1, &value, sizeof(char *), NULL);
1561+
efree(header_name);
15651562
}
15661563

15671564
if (client->current_header_name_allocated) {
@@ -1719,7 +1716,7 @@ static void php_cli_server_client_populate_request_info(const php_cli_server_cli
17191716
request_info->post_data = client->request.content;
17201717
request_info->content_length = request_info->post_data_length = client->request.content_len;
17211718
request_info->auth_user = request_info->auth_password = request_info->auth_digest = NULL;
1722-
if (SUCCESS == zend_hash_find(&client->request.headers, "Content-Type", sizeof("Content-Type"), (void**)&val)) {
1719+
if (SUCCESS == zend_hash_find(&client->request.headers, "content-type", sizeof("content-type"), (void**)&val)) {
17231720
request_info->content_type = *val;
17241721
}
17251722
} /* }}} */
@@ -1957,7 +1954,7 @@ static int php_cli_server_begin_send_static(php_cli_server *server, php_cli_serv
19571954
static int php_cli_server_request_startup(php_cli_server *server, php_cli_server_client *client TSRMLS_DC) { /* {{{ */
19581955
char **auth;
19591956
php_cli_server_client_populate_request_info(client, &SG(request_info));
1960-
if (SUCCESS == zend_hash_find(&client->request.headers, "Authorization", sizeof("Authorization"), (void**)&auth)) {
1957+
if (SUCCESS == zend_hash_find(&client->request.headers, "authorization", sizeof("authorization"), (void**)&auth)) {
19611958
php_handle_auth_data(*auth TSRMLS_CC);
19621959
}
19631960
SG(sapi_headers).http_response_code = 200;

sapi/cli/tests/bug65633.phpt

Lines changed: 48 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,48 @@
1+
--TEST--
2+
Bug #65633 (built-in server treat some http headers as case-sensitive)
3+
--SKIPIF--
4+
<?php
5+
include "skipif.inc";
6+
?>
7+
--FILE--
8+
<?php
9+
include "php_cli_server.inc";
10+
php_cli_server_start(<<<'PHP'
11+
var_dump($_COOKIE, $_SERVER['HTTP_FOO']);
12+
PHP
13+
);
14+
15+
list($host, $port) = explode(':', PHP_CLI_SERVER_ADDRESS);
16+
$port = intval($port)?:80;
17+
18+
$fp = fsockopen($host, $port, $errno, $errstr, 0.5);
19+
if (!$fp) {
20+
die("connect failed");
21+
}
22+
23+
if(fwrite($fp, <<<HEADER
24+
GET / HTTP/1.1
25+
cookie: foo=bar
26+
foo: bar
27+
28+
29+
HEADER
30+
)) {
31+
while (!feof($fp)) {
32+
echo fgets($fp);
33+
}
34+
}
35+
36+
fclose($fp);
37+
?>
38+
--EXPECTF--
39+
HTTP/1.1 200 OK
40+
Connection: close
41+
X-Powered-By: %s
42+
Content-type: text/html
43+
44+
array(1) {
45+
["foo"]=>
46+
string(3) "bar"
47+
}
48+
string(3) "bar"

0 commit comments

Comments
 (0)