View Issue Details
|ID||Project||Category||View Status||Date Submitted||Last Update|
|0001608||Xdebug||Usage problems (Wrong Results)||public||2019-01-15 14:30||2019-01-22 22:08|
|Target Version||Fixed in Version|
|Summary||0001608: XDEBUG_CONFIG env var make sessions automatically START ever (at least send the XDEBUG_SESSION cookie)|
|Description||I think i've found a great bug inthe XDEBUG sources (linked to my previous issue 0001604 not yet answered).|
My problem was that i've set (for any need) an EMPTY env var called XDEBUG_CONFIG, this make XDEBUG ALWAYS write a XDEBUG_SESSION cookie in response to any request, with the default IDE key.
This is a security issue as anyone is able to know that XDEBUG is enabled. (i was protected as used a firewalled dbgp-proxy, but it is a security issue)
THIS also make XDEBUG ever try to contact the xdebug.remote_host EVER when remote_enable=0 or remote_autostart=0
causing PERFORMANCE ISSUES (a call to the proxy/IDE for ALL the requests)
I arrived to this problem trough reading the C source and i saw this line:
I'm not actually a C developer but wrote some driver in the past so i can quickly understand that getenv() return NULL only when the ENV_VAR *does not exist*... when it is empty getenv() return an empty string that in that IF evaluate to TRUE.
Actually i'm unable to make a fix/PR as i dont touch C lang since some time, so please make a PR yourself and TAG me on github if you have pleasure (my GitHub account is aledelgo)
|Steps To Reproduce||Set this in the php-fpm pool setting|
env[XDEBUG_CONFIG] = $XDEBUG_CONFIG
set the env as empty on your system
set this settings on php.ini
call any php file.
the return request ALWAY try to write a cookie
if you set
the remote_host will be EVER contacted, also when the request doesn't include any xdebug session trigger.
|Tags||No tags attached.|
i've tried to fix and make a PR on the fly...
don't blame me for the rude attempt.
hope you can improve it.
||I can see there is something odd going on here. I don't think your fix is correct, but I will have a look once Xdebug 2.7.0 has been released. Thanks for reporting this issue!|
|2019-01-15 14:30||alexo||New Issue|
|2019-01-15 14:58||alexo||Note Added: 0004805|
|2019-01-22 22:08||derick||Note Added: 0004827|
|2019-01-22 22:08||derick||Assigned To||=> derick|
|2019-01-22 22:08||derick||Status||new => acknowledged|
|2019-01-22 22:11||derick||Relationship added||has duplicate 0001604|