php.net |  support |  documentation |  report a bug |  advanced search |  search howto |  statistics |  random bug |  login
Doc Bug #61893 The $_REQUEST Predefined Variable Does NOT Contains the Contents of $_COOKIE
Submitted: 2012-05-02 01:11 UTC Modified: 2013-10-09 06:23 UTC
Votes:14
Avg. Score:1.5 ± 1.1
Reproduced:2 of 3 (66.7%)
Same Version:-1 (-50.0%)
Same OS:-1 (-50.0%)
From: marcoscanrib at ig dot com dot br Assigned: krakjoe (profile)
Status: Closed Package: Documentation problem
PHP Version: 5.3Git-2012-05-02 (Git) OS: Windows XP Prof
Private report: No CVE-ID: None
Welcome back! If you're the original bug submitter, here's where you can edit the bug or add additional notes.
If you forgot your password, you can retrieve your password here.
Password:
Status:
Package:
Bug Type:
Summary:
From: marcoscanrib at ig dot com dot br
New email:
PHP Version: OS:

 

 [2012-05-02 01:11 UTC] marcoscanrib at ig dot com dot br
Description:
------------
---
From manual page: http://www.php.net/reserved.variables.request#refsect1-
reserved.variables.request-description
---


Test script:
---------------
<?php
// set the cookies
setcookie("CookieName1", 1);
setcookie("CookieName2", "two");
setcookie("CookieName3", "Cookie 3");
?>

// prints the elements of the $_COOKIE array
<pre>
<?php print_r($_COOKIE); ?>
</pre>

// prints the elements of the $_REQUEST array
<pre>
<?php print_r($_REQUEST); ?>
</pre>

Expected result:
----------------
IF the $_REQUEST predefined array contained the contents of the $_COOKIE 
predefined array, as stated at 
http://docs.php.net/manual/en/reserved.variables.request.php, the above script 
should display : 

Array
(
    [CookieName1] => 1
    [CookieName2] => two
    [CookieName3] => Cookie 3
)
Array
(
    [CookieName1] => 1
    [CookieName2] => two
    [CookieName3] => Cookie 3
)


Actual result:
--------------
The above script displays, that clearly demonstrate that $_REQUEST does NOT 
contain the contents of $_COOKIE. I consider the real content of the $_REQUEST 
array fine, better than if it also included the contents of the $_COOKIE array. 
For me, only the documentation is wrong and should be corrected, what is very 
easy indeed.

Array
(
    [CookieName1] => 1
    [CookieName2] => two
    [CookieName3] => Cookie 3
)
Array
(
)



Patches

Pull Requests

History

AllCommentsChangesGit/SVN commitsRelated reports
 [2012-05-02 01:22 UTC] aharvey@php.net
The documentation already states clearly that that's the default behaviour only 
and can be changed via variables_order and request_order.
 [2012-05-02 01:22 UTC] aharvey@php.net
-Status: Open +Status: Wont fix
 [2012-05-03 02:08 UTC] marcoscanrib at ig dot com dot br
Congratulations for the quick follow up of the users feedbacks. 

About your follow up content, I add that I have not used variables_order nor 
request_order to change the default behavior of the $_REQUEST array and I got the 
results I stated. So, at least in my PHP installation (XAMPP), the default 
behavior of the $_REQUEST is NOT to include the contents of $_COOKIE. Is there a 
way to check if XAMPP changed the default behaviour of the $_REQUEST array ?
 [2012-05-03 02:24 UTC] marcoscanrib at ig dot com dot br
I have just searched the documentation for the 'request_order' directive and it 
clearly states : "Note that the >>default<< distribution php.ini files does not 
contain the 'C' for cookies". 

So, I believe this proves that, >>by default<<, $_REQUEST does NOT include the 
contents of $_COOKIE and that the following statement in the documentation is 
wrong and should be fixed : "Description : An associative array that by default 
contains the contents of $_GET, $_POST and $_COOKIE."
 [2012-08-28 14:23 UTC] kim dot rowan at cancer dot org dot uk
I would also like to see the documentation updated to reflect the accurate circumstances where $_REQUEST would incorporate $_COOKIE data alongside $_GET and $_POST as it is currently misleading.
 [2012-08-28 18:54 UTC] philip@php.net
-Status: Wont fix +Status: Re-Opened
 [2012-08-28 18:54 UTC] philip@php.net
The meaning of "default" here is debatable and will never please everyone. But 
the request_order documentation shows "" as its default, but does also refer to 
the distributed php.ini-* files. 

The default value is what PHP would do without a php.ini file. Different 
distributions (Linux variants, or packages like the aforementioned XAMPP, and the 
like) choose either php.ini-production/php.ini-recommended, or use neither, or 
sets custom values, so really the meaning of "default" is unclear. This is why we 
use the non-php.ini value as the default. It's simple.

And just to be clear. PHP does not ship with a "php.ini" file as instead one must 
manually rename one of the two example files.

But that description is unclear so this bug report now requests that:

A) This be rewritten "Note that the default distribution php.ini files does not 
contain the 'C' for cookies, due to security concerns." as it's strange.

B) We have a FAQ entry about what a "default" value means. One that is more 
descriptive than our current docs on the matter. It should refer to both php.ini-
* files, that default is non-php.ini, and maybe even mention the -n cli option.

I thought we already did something like (B) but I cannot find.
 [2013-10-09 06:23 UTC] krakjoe@php.net
-Status: Re-Opened +Status: Closed -Assigned To: +Assigned To: krakjoe
 [2013-10-09 06:23 UTC] krakjoe@php.net
_REQUEST contains the *REQUEST* cookies, you should not expect to find your *RESPONSE* in _REQUEST ...

I don't see that there is a problem, closing the bug.
 
PHP Copyright © 2001-2026 The PHP Group
All rights reserved.
Last updated: Tue Oct 06 06:00:01 2026 UTC