Hacktoberfest 2026: as issues que os mantenedores marcaram para outubro, abertas e boas para iniciantes. Ver issues do Hacktoberfest

SoapClient only strips `Authorization: Basic` when a WSDL imports from another host

Aberta
#23,686 10 comentários 0 reações 1 responsável Ver no GitHub

Mantenedores costumam responder em até 1 dia

@DanielEScherzer já está trabalhando nisso.

Desde 15/9/2026.

  • #23698 de @DanielEScherzer — aberto

Avaliação

Esta issue ainda não foi avaliada.

Descrição

Bug Status: Needs Triage
Description

Originally reported by @christos-cantina-security.

When a WSDL imports a schema or another WSDL from a different host, SoapClient clears the credentials from the stream context before fetching it in sdl_set_uri_credentials() @ ext/soap/php_sdl.c. The strip only matches the exact string Authorization: Basic in http.header, and only when that option is a string. The TODO right above it already notes that the array form of http.header is not handled.

Any other credential passes through to the third-party host as-is: a Bearer or Digest Authorization header, a lowercase authorization: header, a Cookie header, a Proxy-Authorization header, and every header given as an array.

The following code, with https://a.example serving a WSDL that contains <xsd:import schemaLocation="https://b.example/schema.xsd"/>:

<?php
$client = new SoapClient('https://a.example/service.wsdl', [
    'cache_wsdl' => WSDL_CACHE_NONE,
    'stream_context' => stream_context_create([
        'http' => ['header' => "Authorization: Bearer secret-token\r\n"],
    ]),
]);

Resulted in this request on b.example:

GET /schema.xsd HTTP/1.1
Host: b.example
Authorization: Bearer secret-token

But I expected the header to be dropped on the host change, like Authorization: Basic already is:

GET /schema.xsd HTTP/1.1
Host: b.example

This should be hardened on master, potentially introducing a BC break:

  • strip every Authorization, Proxy-Authorization and Cookie header, case-insensitively
  • handle the array form of http.header, resolving the existing TODO
  • add a SoapClient option to keep the headers for setups where the same credentials serve both hosts
  • document the behavior change in UPGRADING
PHP Version
master
Operating System

No response

Linguagem predominante
C
Estrelas
40.4k
Forks
8.2k
Merge médio
2d 7h
PRs com merge (30d)
153

Preparar o ambiente

Primeiros passos

  1. Leia a issue inteira e depois o guia de contribuição do projeto.
  2. Comente na issue dizendo que vai assumir — evita que duas pessoas façam o mesmo trabalho.
  3. Faça um fork do repositório e trabalhe em uma branch.
  4. Abra um pull request que referencie o número da issue.

Mais de php/php-src

Todas as issues de php/php-src

Issues semelhantes

Mais issues de C

Receba novas issues na sua caixa de entrada

Um resumo curto de issues do GitHub para quem está começando.