Skip to content

fix: keep $_REQUEST in sync with rewritten GET in SiteURIFactory - #10575

Open
DarpanAdhikari wants to merge 1 commit into
codeigniter4:developfrom
DarpanAdhikari:oss/20260920-0111
Open

DarpanAdhikari wants to merge 1 commit into
codeigniter4:developfrom
DarpanAdhikari:oss/20260920-0111

Conversation

@DarpanAdhikari

Copy link
Copy Markdown

What does this PR do?

Fixes getVar() returning stale GET values after the route path is rewritten from the query string.

What is the fix?

SiteURIFactory::detectRoutePath() rewrites a raw REQUEST_URI/QUERY_STRING into a correct one (e.g. /index.php?/ci/woot?code=good#pos -> query code=good). It already mirrored the corrected values into $_GET via parseRequestURI()/parseQueryString(), but not into $_REQUEST.

getVar() and validation read from $_REQUEST (not $_GET), so getVar('code') returned the stale/unset value from the pre-rewrite $_REQUEST, and $_REQUEST never reflected the corrected GET values.

This PR keeps $_REQUEST in sync with the rewritten GET values in both detection paths (parseRequestURI() + parseQueryString()) via a shared syncRequestWithGet() helper, so getVar('code') returns 'good' as expected. Only GET-originated keys are updated; POST/COOKIE values are left untouched.

Why is this needed?

Without it, getVar('code') (and validation reading the same $_REQUEST source) returns an empty/stale value for the rewritten key even though $_GET['code'] is correct.

Related

  • Opening for the Pull Shark/achievements theme; happy to add more GET/REQUEST coverage if maintainers want it.

Checklist

  • Tests added
  • php -l on both changed files
  • Local phpunit bootstrap requires ext-intl (Locale) which this sandbox lacks; harness could not fully boot. Logic verified via standalone harness reproducing the detectRoutePath GET/REQUEST rewrite. CI (with ext-intl) will run full suite.

getVar() and validation read from $_REQUEST rather than $_GET. When the
query string is rewritten by detectRoutePath() (e.g. /index.php?/ci/woot?code=good),
the corrected GET values were only written to $_GET, leaving $_REQUEST stale,
so getVar('code') returned the unset value.

Both parseRequestURI() and parseQueryString() now mirror the parsed GET
values into $_REQUEST so getVar()/validation see the corrected data.
@mergeable

mergeable Bot commented Sep 19, 2026

Copy link
Copy Markdown

Hi there, DarpanAdhikari! 👋

Thank you for sending this PR!

We expect the following in all Pull Requests (PRs).

Important

We expect all code changes or bug-fixes to be accompanied by one or more tests added to our test suite to prove the code works.

If pull requests do not comply with the above, they will likely be closed. Since we are a team of volunteers, we don't have any more time to work
on the framework than you do. Please make it as painless for your contributions to be included as possible.

See https://github.com/codeigniter4/CodeIgniter4/blob/develop/contributing/pull_request.md

Sincerely, the mergeable bot 🤖

@carson-codeigniter4 carson-codeigniter4 Bot added the bug Verified issues on the current code behavior or pull requests that will fix them label Sep 19, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bug Verified issues on the current code behavior or pull requests that will fix them

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant