-
Notifications
You must be signed in to change notification settings - Fork 8k
add php.ini entry to set default user_agent for curl #6834
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Closed
Closed
Changes from 6 commits
Commits
Show all changes
7 commits
Select commit
Hold shift + click to select a range
eee7fdb
add php.ini entry to set default user_agent for curl
paresy 44d256f
change ini scope to PHP_INI_ALL
paresy 05d986c
add test
paresy 05ab771
add ini setting into php.ini-*
paresy 7bd062a
Update php.ini-development
paresy 9e8ac5e
Update php.ini-development
paresy 30c0f96
Update ext/curl/tests/curl_user_agent.phpt
paresy File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,56 @@ | ||
--TEST-- | ||
Test curl.user_agent ini entry | ||
--INI-- | ||
curl.user_agent=test/1.0 | ||
--SKIPIF-- | ||
<?php include 'skipif.inc'; ?> | ||
cmb69 marked this conversation as resolved.
Outdated
Show resolved
Hide resolved
|
||
--FILE-- | ||
<?php | ||
|
||
include 'server.inc'; | ||
$host = curl_cli_server_start(); | ||
|
||
$ch = curl_init($host); | ||
curl_setopt($ch, CURLOPT_RETURNTRANSFER, true); | ||
curl_setopt($ch, CURLINFO_HEADER_OUT, true); | ||
curl_exec($ch); | ||
$info = curl_getinfo($ch); | ||
echo $info['request_header']; | ||
curl_close($ch); | ||
|
||
ini_set('curl.user_agent', 'ini/1.0'); | ||
|
||
//Override with ini_set | ||
$ch = curl_init($host); | ||
curl_setopt($ch, CURLOPT_RETURNTRANSFER, true); | ||
curl_setopt($ch, CURLINFO_HEADER_OUT, true); | ||
curl_exec($ch); | ||
$info = curl_getinfo($ch); | ||
echo $info['request_header']; | ||
curl_close($ch); | ||
|
||
//Override with CURLOPT | ||
$ch = curl_init($host); | ||
curl_setopt($ch, CURLOPT_RETURNTRANSFER, true); | ||
curl_setopt($ch, CURLOPT_USERAGENT, 'override/1.0'); | ||
curl_setopt($ch, CURLINFO_HEADER_OUT, true); | ||
curl_exec($ch); | ||
$info = curl_getinfo($ch); | ||
echo $info['request_header']; | ||
curl_close($ch); | ||
?> | ||
--EXPECTREGEX-- | ||
GET \/ HTTP\/1\.1 | ||
Host: localhost:[0-9]* | ||
User-Agent: test\/1.0 | ||
Accept: \*\/\* | ||
|
||
GET \/ HTTP\/1\.1 | ||
Host: localhost:[0-9]* | ||
User-Agent: ini\/1.0 | ||
Accept: \*\/\* | ||
|
||
GET \/ HTTP\/1\.1 | ||
Host: localhost:[0-9]* | ||
User-Agent: override\/1.0 | ||
Accept: \*\/\* |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
|
@@ -872,7 +872,8 @@ allow_url_include = Off | |
; https://php.net/from | ||
;from="[email protected]" | ||
|
||
; Define the User-Agent string. PHP's default setting for this is empty. | ||
; Define the User-Agent when using the HTTP wrapper (e.g. file_get_contents). PHP's default setting for this is empty. | ||
; See curl.user_agent when using cURL for requests | ||
; https://php.net/user-agent | ||
;user_agent="PHP" | ||
|
||
|
@@ -1919,6 +1920,10 @@ ldap.max_links = -1 | |
; absolute path. | ||
;curl.cainfo = | ||
|
||
; Define the User-Agent when using cURL for requests. When this is empty or unset, curl's default user agent is used instead. | ||
; See user_agent (without prefix) to set the User-Agent when using the HTTP wrapper (e.g. file_get_contents) | ||
;curl.user_agent="PHP" | ||
|
||
[openssl] | ||
; The location of a Certificate Authority (CA) file on the local filesystem | ||
; to use when verifying the identity of SSL/TLS peers. Most users should | ||
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
|
@@ -874,7 +874,8 @@ allow_url_include = Off | |
; https://php.net/from | ||
;from="[email protected]" | ||
|
||
; Define the User-Agent string. PHP's default setting for this is empty. | ||
; Define the User-Agent when using the HTTP wrapper (e.g. file_get_contents). PHP's default setting for this is empty. | ||
; See curl.user_agent when using cURL for requests | ||
; https://php.net/user-agent | ||
;user_agent="PHP" | ||
|
||
|
@@ -1921,6 +1922,11 @@ ldap.max_links = -1 | |
; absolute path. | ||
;curl.cainfo = | ||
|
||
; Define the User-Agent when using cURL for requests. PHP's default setting for this is empty. | ||
; See user_agent (without prefix) to set the User-Agent when using the HTTP wrapper (e.g. file_get_contents) | ||
; https://php.net/curl-user-agent | ||
;curl.user_agent="PHP" | ||
|
||
[openssl] | ||
; The location of a Certificate Authority (CA) file on the local filesystem | ||
; to use when verifying the identity of SSL/TLS peers. Most users should | ||
|
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Uh oh!
There was an error while loading. Please reload this page.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
After thinking about it more, I'd personally be in favor of PHP_INI_SYSTEM but would be opposed to the permissive PHP_INI_ALL. PHP_INI_SYSTEM would forbid calling ini_set at runtime, but still allow system configuration.
See https://www.php.net/manual/en/configuration.changes.modes.php and https://www.php.net/manual/en/configuration.changes.php (e.g. for web servers that use apache, the setting can be set in php.ini, and/or overridden for individual apache virtual hosts in /etc/httpd/vhosts.d/ with
php_value
)php -d curl.user_agent='Some user agent' myCLIScript.php
would also always work if different CLI applications needed different user agentsThe reason I think the ability to call ini_set at runtime might be a problem:
If an application has two libraries that use the default curl user agent (libA and libB), and LibA were to call
ini_set('curl.user_agent', 'LibA/1.2.3')
and not bother to restore the user agent (or throw, etc), then the application would unexpectedly and spuriously sometimes call the endpoints that libB calls with the wrong user agent of LibA.Async frameworks using generators and php 8.1's fibers would make that a larger concern
So the application using LibB calling ServerB with a user agent from LibA may cause issues, such as developers wasting time debugging because of being mislead about what the service's caller actually is, or ServerB parsing the wrong versions from the user agent, or ServerB rejecting requests because the user agent is unrecognized or forbidden
Obviously, for
file_get_contents
, there's no way to override the user agent, so it's useful thatuser_agent
can be overridden at runtime. But curl_setopt can already override the user agentThere was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Sorry for the late response. As far as i have checked you can override the user_agent during runtime using file_get_contents. Therefore i wanted to keep curl.user_agent in the same mode as the original user_agent.
This is my code to verify this:
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
That only affects the call in question - I'm talking about ini_set affecting completely unrelated libraries that don't share a context
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
That is correct, but wouldn't that also apply for the global user_agent option? If i have understood correctly the user_agent option will have the same "unwanted" affect. If we want to fix this problem, shouldn't we also limit the global user_agent option to PHP_INI_SYSTEM? (Which will be hard due to a quite hard BC break)
Anyway. I can gladly change to PHP_INI_SYSTEM if no one is against this change.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Didn't realize that - I think the vast majority of calls to file_get_contents don't typically use a context, and curl is typically preferred (easier to set timeouts(lookup/request/connect), redirect behavior, allowed protocols, etc).
Also, in general, php aims for consistency within a module(aka php extension) (e.g.
ext/curl
) (individual modules do/may differ greatly from each other for naming, class/function usage, etc), which is why I personally strongly prefer PHP_INI_SYSTEM