|  support |  documentation |  report a bug |  advanced search |  search howto |  statistics |  random bug |  login
Bug #78207 setrawcookie does not not behave like setcookie when overwriting
Submitted: 2019-06-25 15:12 UTC Modified: 2019-06-25 15:31 UTC
From: nico at billiotte dot fr Assigned:
Status: Not a bug Package: Unknown/Other Function
PHP Version: 7.3.6 OS: OSX + linux
Private report: No CVE-ID: None
Welcome back! If you're the original bug submitter, here's where you can edit the bug or add additional notes.
If this is not your bug, you can add a comment by following this link.
If this is your bug, but you forgot your password, you can retrieve your password here.
Bug Type:
From: nico at billiotte dot fr
New email:
PHP Version: OS:


 [2019-06-25 15:12 UTC] nico at billiotte dot fr
From manual page:

Test script:
$id = $_REQUEST['id'];
$val = $_REQUEST['val'];

if( isset($_COOKIE['testcookie']) ){
     $cookie = json_decode($_COOKIE['testcookie'], true);

$moncookie[$id] = $val;
setrawcookie('testcookie', json_encode($cookie), 0, '/');

Expected result:
send id = 1 & val = "foo"
cookie = {1:foo} -> correct

then resend id = 2 & val = "bar"
cookie should contain {1:foo, 2:bar}

Actual result:
the cookie remains nothing changes
{1:foo} -> not correct

change setrawcookie by setcookie and add urldecode() and everything is fine you can "update" the cookie


Add a Patch

Pull Requests

Add a Pull Request


AllCommentsChangesGit/SVN commitsRelated reports
 [2019-06-25 15:31 UTC]
-Status: Open +Status: Not a bug
 [2019-06-25 15:31 UTC]
Thank you for taking the time to write to us, but this is not
a bug. Please double-check the documentation available at and the instructions on how to report
a bug at

This is the correct, intended behaviour - it is caused by the specific value for the cookie, rather than the general behaviour of the function.

If you turn on error reporting, you will find that the following warning is emitted:

> Warning: Cookie values cannot contain any of the following ',; \t\r\n\013\014' in ...

This is due to the syntax of the Cookie header in the HTTP protocol. The solution to this problem is to use setcookie() instead of setrawcookie(), which will correctly encode the values.

This issue arises because the JSON generated by the first request does not contain a comma, the second request adds a second element separated by a comma.
PHP Copyright © 2001-2022 The PHP Group
All rights reserved.
Last updated: Thu Jul 07 14:03:34 2022 UTC