Repository navigation
fix: refresh REQUEST after URI GET normalization - #10606
rahul05ranjan wants to merge 2 commits into
Conversation
|
@paulbalandan The new PR's workflows are waiting for approval to run. Could you approve them when you get to this review? Here's the PHPUnit run; the focused local results are in the PR description. |
michalsn
left a comment
There was a problem hiding this comment.
Overall, I think this looks good.
| * | ||
| * @return array<string, request_items> | ||
| */ | ||
| public function getRequestData(?string $requestOrder = null): array |
There was a problem hiding this comment.
I think this method should be marked as "internal".
There was a problem hiding this comment.
🟡 Changes recommended
The new tests depend on the host’s request_order, and SiteURIFactory’s PHPDoc omits its new $_REQUEST side effect.
3 open findings
What changed in this PR
Fixes stale $_REQUEST values after URI query normalization while preserving custom entries.
Changes:
- Adds configured GET/POST/COOKIE merging.
- Refreshes source-derived REQUEST entries during URI parsing.
- Adds regression tests and changelog documentation.
Base branch was unavailable; develop compatibility policy was applied. A focused PHP runtime probe passed; full validation remains with CI.
| File | Description |
|---|---|
system/Superglobals.php |
Adds merged request-data retrieval. |
system/HTTP/SiteURIFactory.php |
Refreshes REQUEST after GET normalization. |
tests/system/SuperglobalsTest.php |
Tests request merging semantics. |
tests/system/HTTP/SiteURIFactoryDetectRoutePathTest.php |
Tests URI normalization regressions. |
user_guide_src/source/changelogs/v4.7.5.rst |
Documents the fix. |
🧠 Review effort: Balanced
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
|
|
||
| $factory = new SiteURIFactory(new App(), $superglobals); | ||
|
|
||
| $this->assertSame('ci/woot', $factory->detectRoutePath('QUERY_STRING')); |
| $this->superglobals->setGetArray(['get_key' => 'get_value']); | ||
| $this->superglobals->setPostArray(['post_key' => 'post_value']); | ||
|
|
||
| $data = $this->superglobals->getRequestData(); |
| } | ||
|
|
||
| // Update our global GET for values likely to have been changed | ||
| // Refresh only the request values derived from superglobals after GET changes. |


Description
Fixes #9872.
SiteURIFactorycan normalize$_GETafter PHP has populated$_REQUEST, leaving stale query values forgetVar()andValidation::withRequest(). This follows the direction agreed on in #10587: refresh REQUEST once during URI parsing while keepinggetVar()'s existing lookup behavior.Summary
Superglobals::getRequestData()provides the merged source data in PHP's configured order. Both URI parsing paths use it before and after GET normalization. No general synchronization is added tosetGetArray().Evidence
develop: the old query key remains in REQUEST, andcodestays stale.After:
SiteURIFactoryDetectRoutePathTest.phppasses (34 tests, 42 assertions), including awithRequest()validation check and preservation of application-set values.SuperglobalsTest.phppasses (56 tests, 115 assertions);SiteURIFactoryTest.phppasses (8 tests, 32 assertions).Merge Danger
Door: Two-way. Reverting the commit restores the previous request initialization behavior.
Blast Radius: Request initialization in the two SiteURIFactory URI parsing paths. An application-defined REQUEST value that is identical to its old merged source value cannot be distinguished from that source value; the refresh treats it as source-derived.
Checklist:
getVar()reference remains accurate