php.net |  support |  documentation |  report a bug |  advanced search |  search howto |  statistics |  random bug |  login
Bug #3028 setcookie outputs wrong format, year not 4-digits
Submitted: 1999-12-22 15:07 UTC Modified: 1999-12-22 17:57 UTC
From: wew at bearnet dot com Assigned:
Status: Closed Package: Misbehaving function
PHP Version: 4.0 Beta 3 OS: Linux 2.0.34
Private report: No CVE-ID: None
 [1999-12-22 15:07 UTC] wew at bearnet dot com
According to http://www.netscape.com/newsref/std/cookie_spec.html: 
   The date string is formatted as: 
             Wdy, DD-Mon-YYYY HH:MM:SS GMT

Output of PHP4's setcookie('browser_id', $b_id, time() + (2 * YEAR), '/', COOKIE_DOMAIN) is: 
   Set-Cookie: browser_id=26; expires=Friday, 21-Dec-01 19:47:53 GMT; path=/; domain=.bearnet.com

The expires part should be: 
   Fri, 21-Dec-2001 19:47:53 GMT

The two-digit year is the most glaring problem, but to be absolutely correct the day-of-week should 
also be fixed (three letters). 

This problem may also exist in PHP3, I haven't checked. 

--Bill

Patches

Pull Requests

History

AllCommentsChangesGit/SVN commitsRelated reports
 [1999-12-22 17:57 UTC] rasmus at cvs dot php dot net
This has been discussed many times.  Not all browsers understand the 4-digit format while they all understand the 2-digit format.
And there is no Y2K issue here either as they properly understand 00 to be 2000.  This is also configurable in the php.ini file for both
PHP 3 and PHP 4

And by the way, if you look down in the example section of the URL you referenced you will see that they use 2-digit years.  The
original version of the spec had 2 digit years so that is what everyone implemented.  They since went back and patched the spec
but didn't bother fixing the examples.
 
PHP Copyright © 2001-2026 The PHP Group
All rights reserved.
Last updated: Sat Oct 10 01:00:02 2026 UTC