php.net |  support |  documentation |  report a bug |  advanced search |  search howto |  statistics |  random bug |  login
Doc Bug #61893 The $_REQUEST Predefined Variable Does NOT Contains the Contents of $_COOKIE
Submitted: 2012-05-02 01:11 UTC Modified: 2013-10-09 06:23 UTC
Votes:14
Avg. Score:1.5 ± 1.1
Reproduced:2 of 3 (66.7%)
Same Version:-1 (-50.0%)
Same OS:-1 (-50.0%)
From: marcoscanrib at ig dot com dot br Assigned: krakjoe (profile)
Status: Closed Package: Documentation problem
PHP Version: 5.3Git-2012-05-02 (Git) OS: Windows XP Prof
Private report: No CVE-ID: None
View Developer Edit
Welcome! If you don't have a Git account, you can't do anything here.
If you reported this bug, you can edit this bug over here.
(description)
Block user comment
Status: Assign to:
Package:
Bug Type:
Summary:
From: marcoscanrib at ig dot com dot br
New email:
PHP Version: OS:

 

 [2012-05-02 01:11 UTC] marcoscanrib at ig dot com dot br
Description:
------------
---
From manual page: http://www.php.net/reserved.variables.request#refsect1-
reserved.variables.request-description
---


Test script:
---------------
<?php
// set the cookies
setcookie("CookieName1", 1);
setcookie("CookieName2", "two");
setcookie("CookieName3", "Cookie 3");
?>

// prints the elements of the $_COOKIE array
<pre>
<?php print_r($_COOKIE); ?>
</pre>

// prints the elements of the $_REQUEST array
<pre>
<?php print_r($_REQUEST); ?>
</pre>

Expected result:
----------------
IF the $_REQUEST predefined array contained the contents of the $_COOKIE 
predefined array, as stated at 
http://docs.php.net/manual/en/reserved.variables.request.php, the above script 
should display : 

Array
(
    [CookieName1] => 1
    [CookieName2] => two
    [CookieName3] => Cookie 3
)
Array
(
    [CookieName1] => 1
    [CookieName2] => two
    [CookieName3] => Cookie 3
)


Actual result:
--------------
The above script displays, that clearly demonstrate that $_REQUEST does NOT 
contain the contents of $_COOKIE. I consider the real content of the $_REQUEST 
array fine, better than if it also included the contents of the $_COOKIE array. 
For me, only the documentation is wrong and should be corrected, what is very 
easy indeed.

Array
(
    [CookieName1] => 1
    [CookieName2] => two
    [CookieName3] => Cookie 3
)
Array
(
)



Patches

Pull Requests

History

AllCommentsChangesGit/SVN commitsRelated reports
 [2012-05-02 01:22 UTC] aharvey@php.net
The documentation already states clearly that that's the default behaviour only 
and can be changed via variables_order and request_order.
 [2012-05-02 01:22 UTC] aharvey@php.net
-Status: Open +Status: Wont fix
 [2012-05-03 02:08 UTC] marcoscanrib at ig dot com dot br
Congratulations for the quick follow up of the users feedbacks. 

About your follow up content, I add that I have not used variables_order nor 
request_order to change the default behavior of the $_REQUEST array and I got the 
results I stated. So, at least in my PHP installation (XAMPP), the default 
behavior of the $_REQUEST is NOT to include the contents of $_COOKIE. Is there a 
way to check if XAMPP changed the default behaviour of the $_REQUEST array ?
 [2012-05-03 02:24 UTC] marcoscanrib at ig dot com dot br
I have just searched the documentation for the 'request_order' directive and it 
clearly states : "Note that the >>default<< distribution php.ini files does not 
contain the 'C' for cookies". 

So, I believe this proves that, >>by default<<, $_REQUEST does NOT include the 
contents of $_COOKIE and that the following statement in the documentation is 
wrong and should be fixed : "Description : An associative array that by default 
contains the contents of $_GET, $_POST and $_COOKIE."
 [2012-08-28 14:23 UTC] kim dot rowan at cancer dot org dot uk
I would also like to see the documentation updated to reflect the accurate circumstances where $_REQUEST would incorporate $_COOKIE data alongside $_GET and $_POST as it is currently misleading.
 [2012-08-28 18:54 UTC] philip@php.net
-Status: Wont fix +Status: Re-Opened
 [2012-08-28 18:54 UTC] philip@php.net
The meaning of "default" here is debatable and will never please everyone. But 
the request_order documentation shows "" as its default, but does also refer to 
the distributed php.ini-* files. 

The default value is what PHP would do without a php.ini file. Different 
distributions (Linux variants, or packages like the aforementioned XAMPP, and the 
like) choose either php.ini-production/php.ini-recommended, or use neither, or 
sets custom values, so really the meaning of "default" is unclear. This is why we 
use the non-php.ini value as the default. It's simple.

And just to be clear. PHP does not ship with a "php.ini" file as instead one must 
manually rename one of the two example files.

But that description is unclear so this bug report now requests that:

A) This be rewritten "Note that the default distribution php.ini files does not 
contain the 'C' for cookies, due to security concerns." as it's strange.

B) We have a FAQ entry about what a "default" value means. One that is more 
descriptive than our current docs on the matter. It should refer to both php.ini-
* files, that default is non-php.ini, and maybe even mention the -n cli option.

I thought we already did something like (B) but I cannot find.
 [2013-10-09 06:23 UTC] krakjoe@php.net
-Status: Re-Opened +Status: Closed -Assigned To: +Assigned To: krakjoe
 [2013-10-09 06:23 UTC] krakjoe@php.net
_REQUEST contains the *REQUEST* cookies, you should not expect to find your *RESPONSE* in _REQUEST ...

I don't see that there is a problem, closing the bug.
 
PHP Copyright © 2001-2026 The PHP Group
All rights reserved.
Last updated: Tue Oct 06 04:00:02 2026 UTC