php.net |  support |  documentation |  report a bug |  advanced search |  search howto |  statistics |  random bug |  login
Doc Bug #47083 Making documentation of header()'s behaviour on Location: headers more specific
Submitted: 2009-01-13 09:47 UTC Modified: 2009-05-08 19:34 UTC
From: skrebbel at gmail dot com Assigned:
Status: Closed Package: Documentation problem
PHP Version: Irrelevant OS: N/A
Private report: No CVE-ID: None
 [2009-01-13 09:47 UTC] skrebbel at gmail dot com
Description:
------------
Note: I added the following as a manual note first, but Thiago Henrique Pojda of php-notes rejected it with the recommendation that I file it as a documentation bug. I make my conclusions based on http://cvs.php.net/viewvc.cgi/php-src/main/SAPI.c?revision=1.232&view=markup.

----
The manual is not completely precise on what PHP does (at least
according to the PHP source in CVS) with Location: headers.

This is the actual behaviour when you specify a Location: header, as
far as I could derive:
 - If in earlier header() calls(*), a status code 201 or 300 - 307 was
already specified, then that status code is retained
 - If no status code was specified, or if the status code specified
earlier is not 201 or 300 ... 307 then:
  - If the request method is GET or HEAD then 302 "Found" is set
  - Otherwise (i.e. for POST or PUT), 303 "See Also" is set.

Finally, if in the same header call you specify a custom status code,
that one is always set (no matter its value), unless changed later
again.

Examples:
 <?php
 header("Location: http://www.foobar.com/");
 ?>
and
 <?php
 header("HTTP/1.1 404 Not Found");
 header("Location: http://www.foobar.com/");
 ?>
set the status code to 302 when called with GET and to 303 when called
with POST, and

 <?php
 header("Location: http://www.foobar.com/", true, 404);
 ?>
and
 <?php
 header("Location: http://www.foobar.com/");
 header("HTTP/1.1 404 Not Found");
 ?>
set the status code to 404.

Note that combining a Location header with a status code other than
201 or 3xx does not really make much sense in HTTP <= 1.1 (hence PHP's
behaviour); as such, the last three examples are just for illustrative
purposes.

(*) either through a header("HTTP/1.1 302 Found") - style call or
through the third argument on a different header() call, i.e.
header("Content-type: text/html", true, 302); (which does not make
much sense, though)


Patches

Pull Requests

History

AllCommentsChangesGit/SVN commitsRelated reports
 [2009-05-08 19:34 UTC] danbrown@php.net
In my opinion, based upon my understanding of this bug report, the 
manual entry describes this sufficiently - for the scope of the 
documentation itself - in the following paragraph:

'The second special case is the "Location:" header. Not only does it 
send this header back to the browser, but it also returns a REDIRECT 
(302) status code to the browser unless some 3xx status code has 
already been set.'

Beyond that, I feel that your contribution in the form of a user note 
was appropriate for the type of material.  Should you be so inclined 
as to resubmit the note, we'll make sure it is not rejected this time 
(though if it mentions key terms that indicate the manual is not 
correct, it may be rejected by another editor in the future to be 
reported again as a bug).

Thanks for your contribution and follow-ups.  We greatly appreciate 
your efforts in support of PHP!
 
PHP Copyright © 2001-2026 The PHP Group
All rights reserved.
Last updated: Tue Oct 06 06:00:01 2026 UTC