[ 
https://issues.apache.org/jira/browse/THRIFT-6362?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=18118609#comment-18118609
 ] 

Jens Geyer commented on THRIFT-6362:
------------------------------------

This change ships in 0.25.0: master was merged into {{release/0.25.0}} for 
RC-1, and the fixVersion is now 0.25.0. The {{lib/php/README.md}} entry 
mentioned in the description is therefore listed under the 0.25.0 breaking 
changes, on {{release/0.25.0}} already and on master with [PR 
#3949|https://github.com/apache/thrift/pull/3949].

_Drafted with AI assistance (Claude Opus 5.5); reviewed and posted by Jens 
Geyer._

> PHP TCurlClient follows HTTP redirects to other origins
> -------------------------------------------------------
>
>                 Key: THRIFT-6362
>                 URL: https://issues.apache.org/jira/browse/THRIFT-6362
>             Project: Thrift
>          Issue Type: Bug
>          Components: PHP - Library
>            Reporter: Jens Geyer
>            Assignee: Jens Geyer
>            Priority: Minor
>              Labels: Breaking-Change
>             Fix For: 0.25.0
>
>          Time Spent: 0.5h
>  Remaining Estimate: 0h
>
> {{TCurlClient}} enables {{CURLOPT_FOLLOWLOCATION}} with {{CURLOPT_MAXREDIRS}} 
> 1 on its shared curl handle, so it follows one redirect wherever the 
> {{Location}} header points. The request, including the headers added through 
> {{addHeaders()}} and, after a 307 or 308, its body, goes again to the scheme, 
> host and port named there, and that server's reply is read as the response. 
> After a 301, 302 or 303 the repeated request still carries the 
> {{Content-Length}} that {{TCurlClient}} sets itself, although curl no longer 
> sends the body, so the call waits for its timeout. {{THttpClient}} does not 
> follow redirects.
> Proposed change: curl no longer follows redirects, and {{TCurlClient}} 
> follows one itself, only within the origin of the configured URL, that is to 
> the same scheme, host and port. It sends the request again, with its headers 
> and body, to the path and query of the redirect target under the configured 
> scheme, host and port. A redirect to another origin, including one from 
> {{http}} to {{https}}, fails the request with a {{TTransportException}}, as 
> any redirect does with {{THttpClient}}. The change is listed under the 0.26.0 
> breaking changes in {{lib/php/README.md}}.
> Reported by Sylwester Lachiewicz.
> _Drafted with AI assistance (Claude Opus 5 and Claude Opus 5.5); reviewed and 
> posted by Jens Geyer._



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to