fix: keep $_REQUEST in sync with rewritten GET in SiteURIFactory - #10575
Open
DarpanAdhikari wants to merge 1 commit into
Open
DarpanAdhikari wants to merge 1 commit into
DarpanAdhikari wants to merge 1 commit into
Conversation
getVar() and validation read from $_REQUEST rather than $_GET. When the
query string is rewritten by detectRoutePath() (e.g. /index.php?/ci/woot?code=good),
the corrected GET values were only written to $_GET, leaving $_REQUEST stale,
so getVar('code') returned the unset value.
Both parseRequestURI() and parseQueryString() now mirror the parsed GET
values into $_REQUEST so getVar()/validation see the corrected data.
|
Hi there, DarpanAdhikari! 👋 Thank you for sending this PR! We expect the following in all Pull Requests (PRs).
Important We expect all code changes or bug-fixes to be accompanied by one or more tests added to our test suite to prove the code works. If pull requests do not comply with the above, they will likely be closed. Since we are a team of volunteers, we don't have any more time to work See https://github.com/codeigniter4/CodeIgniter4/blob/develop/contributing/pull_request.md Sincerely, the mergeable bot 🤖 |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What does this PR do?
Fixes
getVar()returning stale GET values after the route path is rewritten from the query string.What is the fix?
SiteURIFactory::detectRoutePath()rewrites a raw REQUEST_URI/QUERY_STRING into a correct one (e.g./index.php?/ci/woot?code=good#pos-> querycode=good). It already mirrored the corrected values into$_GETviaparseRequestURI()/parseQueryString(), but not into$_REQUEST.getVar()and validation read from$_REQUEST(not$_GET), sogetVar('code')returned the stale/unset value from the pre-rewrite$_REQUEST, and$_REQUESTnever reflected the corrected GET values.This PR keeps
$_REQUESTin sync with the rewritten GET values in both detection paths (parseRequestURI()+parseQueryString()) via a sharedsyncRequestWithGet()helper, sogetVar('code')returns'good'as expected. Only GET-originated keys are updated; POST/COOKIE values are left untouched.Why is this needed?
Without it,
getVar('code')(and validation reading the same$_REQUESTsource) returns an empty/stale value for the rewritten key even though$_GET['code']is correct.Related
Checklist
php -lon both changed filesext-intl(Locale) which this sandbox lacks; harness could not fully boot. Logic verified via standalone harness reproducing the detectRoutePath GET/REQUEST rewrite. CI (with ext-intl) will run full suite.