-pass-headers

Joachim Durchholz <jo-JN0m9dTiHHGb9/[email protected]>
Newsgroups gmane.comp.web.fastcgi.devel
Message-ID <[email protected]>
Hi all,

If this is the wrong list for this question, please point me in the 
right direction.

Question: How do I make sure that all "interesting" headers make it to 
the FastCGI application?

Background infos:
Apache 2.0.49 + mod_fastcgi 2.4.0 (Standard by SuSE 9.1).
Setup is for PHP, with these directives in the <VirtualHost> sections of 
httpd.conf:
    SuexecUserGroup web52 web52
    FastCgiWrapper /usr/sbin/suexec2
    FastCgiConfig -singleThreshold 1
    AddHandler fastcgi-script fcgi fcg fpl
    Action application/x-httpd-php /cgi-bin/php.fcgi
    AddType application/x-httpd-php php php3 php4

Here's the rub:
We're a web hoster, and we don't really know (or care) what PHP scripts 
our customers install. How do we make sure that all headers that any 
script might ever need are passed through?

I already know that -pass-header is part of the answer.
Unfortunately, the mod_fastcgi documentation is extremely vague on the 
topic: "allows passing through headers that are normally not passed 
through". No mention of what the full list of headers is or where to get 
it. No mention which headers are normally passed through, and which 
instance is taken as the "normal case" when it comes to blocking 
headers: Apache, mod_cgi, mod_fastcgi, the CGI protocol, the FastCGI 
protocol.

No wonder that the WWW is entirely confused on the issue, too.
Most configurations have
   -pass-header Authorization
but a large proportion of pages recommends
   -pass-header HTTP_AUTHORIZATION
(Oh, I just found 
http://www.manucorp.com/archives/php-bugs/200512/msg01226.php . It seems 
to indicate that PHP ignores the headers and takes the environment 
variable HTTP_AUTHORIZATION, up to and including at least PHP 4.4.2RC1. 
Now I'm even more confused: an environment variable isn't a header, but 
naming it with -pass-header will pass it on regardless???)

I also found these recommendations:
   -pass-header Cookie
   -pass-header If-Modified-Since
   -pass-header User-Agent
though it's pretty unclear to me whether these are passed through 
normally or not...


Answers anybody? Pointers to docs?

Regards,
Jo

___________________________________
fastcgi-developers mailing list
http://fastcgi.com/fastcgi-developers/
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.