搜索
首页后端开发php教程 php://input是什么意思?php输入流input的引见

php://input是什么意思?php输入流input的介绍

PHP输入流php://input

在使用xml-rpc的时候,server端获取client数据,主要是通过php输入流input,而不是$_POST数组。所以,这里主要探讨php输入流php://input

对一php://input介绍,PHP官方手册文档有一段话对它进行了很明确地概述。

php://input allows you to read raw POST data. It is a less memory intensive alternative to $HTTP_RAW_POST_DATA and does not need any special php.ini directives. php://input is not available with enctype=”multipart/form-data”.
翻译过来,是这样:
“php://input可以读取没有处理过的POST数据。相较于$HTTP_RAW_POST_DATA而言,它给内存带来的压力较小,并且不需要特殊的php.ini设置。php://input不能用于enctype=multipart/form-data”

我们应该怎么去理解这段概述呢?!我把它划分为三部分,逐步去理解。

  1. 读取POST数据
  2. 不能用于multipart/form-data类型
  3. php://input VS $HTTP_RAW_POST_DATA

读取POST数据

PHPer们一定很熟悉$_POST这个内置变量。$_POST与php://input存在哪些关联与区别呢?另外,客户端向服务端交互数据,最常用的方法除了POST之外,还有GET。既然php://input作为PHP输入流,它能读取GET数据吗?这二个问题正是我们这节需要探讨的主要内容。
经验告诉我们,从测试与观察中总结,会是一个很凑效的方法。这里,我写了几个脚本来帮助我们测试。

@file 192.168.0.6:/phpinput_server.php 打印出接收到的数据
@file 192.168.0.8:/phpinput_post.php 模拟以POST方法提交表单数据
@file 192.168.0.8:/phpinput_xmlrpc.php 模拟以POST方法发出xmlrpc请求.
@file 192.168.0.8:/phpinput_get.php 模拟以GET方法提交表单表数

phpinput_server.php与phpinput_post.php

<div class="codesnip-container">
<pre class='brush:php;toolbar:false;'><span class="kw2"><strong><?php</strong></span>
<span class="co1"><span style="color: #808080;">//@file phpinput_server.php</span></span>
<span class="re0">$raw_post_data</span> <span class="sy0">=</span> <span class="kw3"><span style="color: #000066;">file_get_contents</span></span><span class="br0"><span style="color: #66cc66;">(</span></span><span class="st_h">'php://input'</span><span class="sy0">,</span> <span class="st_h">'r'</span><span class="br0"><span style="color: #66cc66;">)</span></span><span class="sy0">;</span>
<span class="kw1"><span style="color: #a1a100;">echo</span></span> <span class="st0"><span style="color: #ff0000;">"-------<span class="es1">\$</span>_POST------------------<span class="es1">\n</span>"</span></span><span class="sy0">;</span>
<span class="kw1"><span style="color: #a1a100;">echo</span></span> <span class="kw3"><span style="color: #000066;">var_dump</span></span><span class="br0"><span style="color: #66cc66;">(</span></span><span class="re0">$_POST</span><span class="br0"><span style="color: #66cc66;">)</span></span> <span class="sy0">.</span> <span class="st0"><span style="color: #ff0000;">"<span class="es1">\n</span>"</span></span><span class="sy0">;</span>
<span class="kw1"><span style="color: #a1a100;">echo</span></span> <span class="st0"><span style="color: #ff0000;">"-------php://input-------------<span class="es1">\n</span>"</span></span><span class="sy0">;</span>
<span class="kw1"><span style="color: #a1a100;">echo</span></span> <span class="re0">$raw_post_data</span> <span class="sy0">.</span> <span class="st0"><span style="color: #ff0000;">"<span class="es1">\n</span>"</span></span><span class="sy0">;</span>
<span class="sy1">?></span>
?
<span class="kw2"><strong><?php</strong></span>
<span class="co1"><span style="color: #808080;">//@file phpinput_post.php</span></span>
<span class="re0">$http_entity_body</span> <span class="sy0">=</span> <span class="st_h">'n='</span> <span class="sy0">.</span> <span class="kw3"><span style="color: #000066;">urldecode</span></span><span class="br0"><span style="color: #66cc66;">(</span></span><span class="st_h">'perfgeeks'</span><span class="br0"><span style="color: #66cc66;">)</span></span> <span class="sy0">.</span> <span class="st_h">'&p='</span> <span class="sy0">.</span> <span class="kw3"><span style="color: #000066;">urldecode</span></span><span class="br0"><span style="color: #66cc66;">(</span></span><span class="st_h">'7788'</span><span class="br0"><span style="color: #66cc66;">)</span></span><span class="sy0">;</span>
<span class="re0">$http_entity_type</span> <span class="sy0">=</span> <span class="st_h">'application/x-www-form-urlencoded'</span><span class="sy0">;</span>
<span class="re0">$http_entity_length</span> <span class="sy0">=</span> <span class="kw3"><span style="color: #000066;">strlen</span></span><span class="br0"><span style="color: #66cc66;">(</span></span><span class="re0">$http_entity_body</span><span class="br0"><span style="color: #66cc66;">)</span></span><span class="sy0">;</span>
<span class="re0">$host</span> <span class="sy0">=</span> <span class="st_h">'192.168.0.6'</span><span class="sy0">;</span>
<span class="re0">$port</span> <span class="sy0">=</span> <span class="nu0"><span style="color: #ff33ff;">80</span></span><span class="sy0">;</span>
<span class="re0">$path</span> <span class="sy0">=</span> <span class="st_h">'/phpinput_server.php'</span><span class="sy0">;</span>
<span class="re0">$fp</span> <span class="sy0">=</span> <span class="kw3"><span style="color: #000066;">fsockopen</span></span><span class="br0"><span style="color: #66cc66;">(</span></span><span class="re0">$host</span><span class="sy0">,</span> <span class="re0">$port</span><span class="sy0">,</span> <span class="re0">$error_no</span><span class="sy0">,</span> <span class="re0">$error_desc</span><span class="sy0">,</span> 30<span class="br0"><span style="color: #66cc66;">)</span></span><span class="sy0">;</span>
<span class="kw1"><span style="color: #a1a100;">if</span></span> <span class="br0"><span style="color: #66cc66;">(</span></span><span class="re0">$fp</span><span class="br0"><span style="color: #66cc66;">)</span></span> <span class="br0"><span style="color: #66cc66;">{</span></span>
  <span class="kw3"><span style="color: #000066;">fputs</span></span><span class="br0"><span style="color: #66cc66;">(</span></span><span class="re0">$fp</span><span class="sy0">,</span> <span class="st0"><span style="color: #ff0000;">"POST <span class="es4">{$path}</span> HTTP/1.1<span class="es1">\r</span><span class="es1">\n</span>"</span></span><span class="br0"><span style="color: #66cc66;">)</span></span><span class="sy0">;</span>
  <span class="kw3"><span style="color: #000066;">fputs</span></span><span class="br0"><span style="color: #66cc66;">(</span></span><span class="re0">$fp</span><span class="sy0">,</span> <span class="st0"><span style="color: #ff0000;">"Host: <span class="es4">{$host}</span><span class="es1">\r</span><span class="es1">\n</span>"</span></span><span class="br0"><span style="color: #66cc66;">)</span></span><span class="sy0">;</span>
  <span class="kw3"><span style="color: #000066;">fputs</span></span><span class="br0"><span style="color: #66cc66;">(</span></span><span class="re0">$fp</span><span class="sy0">,</span> <span class="st0"><span style="color: #ff0000;">"Content-Type: <span class="es4">{$http_entity_type}</span><span class="es1">\r</span><span class="es1">\n</span>"</span></span><span class="br0"><span style="color: #66cc66;">)</span></span><span class="sy0">;</span>
  <span class="kw3"><span style="color: #000066;">fputs</span></span><span class="br0"><span style="color: #66cc66;">(</span></span><span class="re0">$fp</span><span class="sy0">,</span> <span class="st0"><span style="color: #ff0000;">"Content-Length: <span class="es4">{$http_entity_length}</span><span class="es1">\r</span><span class="es1">\n</span>"</span></span><span class="br0"><span style="color: #66cc66;">)</span></span><span class="sy0">;</span>
  <span class="kw3"><span style="color: #000066;">fputs</span></span><span class="br0"><span style="color: #66cc66;">(</span></span><span class="re0">$fp</span><span class="sy0">,</span> <span class="st0"><span style="color: #ff0000;">"Connection: close<span class="es1">\r</span><span class="es1">\n</span><span class="es1">\r</span><span class="es1">\n</span>"</span></span><span class="br0"><span style="color: #66cc66;">)</span></span><span class="sy0">;</span>
  <span class="kw3"><span style="color: #000066;">fputs</span></span><span class="br0"><span style="color: #66cc66;">(</span></span><span class="re0">$fp</span><span class="sy0">,</span> <span class="re0">$http_entity_body</span> <span class="sy0">.</span> <span class="st0"><span style="color: #ff0000;">"<span class="es1">\r</span><span class="es1">\n</span><span class="es1">\r</span><span class="es1">\n</span>"</span></span><span class="br0"><span style="color: #66cc66;">)</span></span><span class="sy0">;</span>
?
  <span class="kw1"><span style="color: #a1a100;">while</span></span> <span class="br0"><span style="color: #66cc66;">(</span></span><span class="sy0">!</span><span class="kw3"><span style="color: #000066;">feof</span></span><span class="br0"><span style="color: #66cc66;">(</span></span><span class="re0">$fp</span><span style="color: #66cc66;"><span class="br0">)</span><span class="br0">)</span></span> <span class="br0"><span style="color: #66cc66;">{</span></span>
    <span class="re0">$d</span> <span class="sy0">.=</span> <span class="kw3"><span style="color: #000066;">fgets</span></span><span class="br0"><span style="color: #66cc66;">(</span></span><span class="re0">$fp</span><span class="sy0">,</span> 4096<span class="br0"><span style="color: #66cc66;">)</span></span><span class="sy0">;</span>
  <span class="br0"><span style="color: #66cc66;">}</span></span>
  <span class="kw3"><span style="color: #000066;">fclose</span></span><span class="br0"><span style="color: #66cc66;">(</span></span><span class="re0">$fp</span><span class="br0"><span style="color: #66cc66;">)</span></span><span class="sy0">;</span>
  <span class="kw1"><span style="color: #a1a100;">echo</span></span> <span class="re0">$d</span><span class="sy0">;</span>
<span class="br0"><span style="color: #66cc66;">}</span></span>
<span class="sy1">?></span>

我们可以通过使用工具ngrep抓取http请求包(因为我们需要探知的是php://input,所以我们这里只抓取http Request数据包)。我们来执行测试脚本phpinput_post.php

<span class="sy0">@</span>php <span class="sy0">/</span>phpinput_post.php
HTTP/1.1 200 OK
Date: Thu, 08 Apr 2010 03:23:36 GMT
Server: Apache/2.2.3 (CentOS)
X-Powered-By: PHP/5.1.6
Content-Length: 160
Connection: close
Content-Type: text/html; charset=UTF-8
-------$_POST------------------
array(2) {
  ["n"]=> string(9) "perfgeeks"
  ["p"]=> string(4) "7788"
}
-------php://input-------------
<strong>n=perfgeeks&p=7788</strong>

通过ngrep抓到的http请求包如下:

T 192.168.0.8:57846 -> 192.168.0.6:80 [AP]
  <strong>POST</strong> /phpinput_server.php HTTP/1.1..
  Host: 192.168.0.6..<strong>Content-Type: application/x-www-form-urlencoded</strong>..Co
  ntent-Length: 18..Connection: close....<strong>n=perfgeeks&p=7788</strong>....

仔细观察,我们不难发现
1,$_POST数据,php://input 数据与httpd entity body数据是“一致”的
2,http请求中的Content-Type是application/x-www-form-urlencoded ,它表示http请求body中的数据是使用http的post方法提交的表单数据,并且进行了urlencode()处理。
(注:注意加粗部分内容,下文不再提示). http://www.k686.com

我们再来看看脚本phpinput_xmlrpc.php的原文件内容,它模拟了一个POST方法提交的xml-rpc请求。

<div class="codesnip-container">
<pre class='brush:php;toolbar:false;'><span class="kw2"><strong><?php</strong></span>
<span class="co1"><span style="color: #808080;">//@file phpinput_xmlrpc.php</span></span>
<span class="re0">$http_entity_body</span> <span class="sy0">=</span> <span class="st0"><span style="color: #ff0000;">"<span class="es1">\n</span><span class="es1">\n</span>   jt_userinfo<span class="es1">\n</span>"</span></span><span class="sy0">;</span>
<span class="re0">$http_entity_type</span> <span class="sy0">=</span> <span class="st_h">'text/html'</span><span class="sy0">;</span>
<span class="re0">$http_entity_length</span> <span class="sy0">=</span> <span class="kw3"><span style="color: #000066;">strlen</span></span><span class="br0"><span style="color: #66cc66;">(</span></span><span class="re0">$http_entity_body</span><span class="br0"><span style="color: #66cc66;">)</span></span><span class="sy0">;</span>
<span class="re0">$host</span> <span class="sy0">=</span> <span class="st_h">'192.168.0.6'</span><span class="sy0">;</span>
<span class="re0">$port</span> <span class="sy0">=</span> <span class="nu0"><span style="color: #ff33ff;">80</span></span><span class="sy0">;</span>
<span class="re0">$path</span> <span class="sy0">=</span> <span class="st_h">'/phpinput_server.php'</span><span class="sy0">;</span>
<span class="re0">$fp</span> <span class="sy0">=</span> <span class="kw3"><span style="color: #000066;">fsockopen</span></span><span class="br0"><span style="color: #66cc66;">(</span></span><span class="re0">$host</span><span class="sy0">,</span> <span class="re0">$port</span><span class="sy0">,</span> <span class="re0">$error_no</span><span class="sy0">,</span> <span class="re0">$error_desc</span><span class="sy0">,</span> 30<span class="br0"><span style="color: #66cc66;">)</span></span><span class="sy0">;</span>
<span class="kw1"><span style="color: #a1a100;">if</span></span> <span class="br0"><span style="color: #66cc66;">(</span></span><span class="re0">$fp</span><span class="br0"><span style="color: #66cc66;">)</span></span> <span class="br0"><span style="color: #66cc66;">{</span></span>
  <span class="kw3"><span style="color: #000066;">fputs</span></span><span class="br0"><span style="color: #66cc66;">(</span></span><span class="re0">$fp</span><span class="sy0">,</span> <span class="st0"><span style="color: #ff0000;">"POST <span class="es4">{$path}</span> HTTP/1.1<span class="es1">\r</span><span class="es1">\n</span>"</span></span><span class="br0"><span style="color: #66cc66;">)</span></span><span class="sy0">;</span>
  <span class="kw3"><span style="color: #000066;">fputs</span></span><span class="br0"><span style="color: #66cc66;">(</span></span><span class="re0">$fp</span><span class="sy0">,</span> <span class="st0"><span style="color: #ff0000;">"Host: <span class="es4">{$host}</span><span class="es1">\r</span><span class="es1">\n</span>"</span></span><span class="br0"><span style="color: #66cc66;">)</span></span><span class="sy0">;</span>
  <span class="kw3"><span style="color: #000066;">fputs</span></span><span class="br0"><span style="color: #66cc66;">(</span></span><span class="re0">$fp</span><span class="sy0">,</span> <span class="st0"><span style="color: #ff0000;">"Content-Type: <span class="es4">{$http_entity_type}</span><span class="es1">\r</span><span class="es1">\n</span>"</span></span><span class="br0"><span style="color: #66cc66;">)</span></span><span class="sy0">;</span>
  <span class="kw3"><span style="color: #000066;">fputs</span></span><span class="br0"><span style="color: #66cc66;">(</span></span><span class="re0">$fp</span><span class="sy0">,</span> <span class="st0"><span style="color: #ff0000;">"Content-Length: <span class="es4">{$http_entity_length}</span><span class="es1">\r</span><span class="es1">\n</span>"</span></span><span class="br0"><span style="color: #66cc66;">)</span></span><span class="sy0">;</span>
  <span class="kw3"><span style="color: #000066;">fputs</span></span><span class="br0"><span style="color: #66cc66;">(</span></span><span class="re0">$fp</span><span class="sy0">,</span> <span class="st0"><span style="color: #ff0000;">"Connection: close<span class="es1">\r</span><span class="es1">\n</span><span class="es1">\r</span><span class="es1">\n</span>"</span></span><span class="br0"><span style="color: #66cc66;">)</span></span><span class="sy0">;</span>
  <span class="kw3"><span style="color: #000066;">fputs</span></span><span class="br0"><span style="color: #66cc66;">(</span></span><span class="re0">$fp</span><span class="sy0">,</span> <span class="re0">$http_entity_body</span> <span class="sy0">.</span> <span class="st0"><span style="color: #ff0000;">"<span class="es1">\r</span><span class="es1">\n</span><span class="es1">\r</span><span class="es1">\n</span>"</span></span><span class="br0"><span style="color: #66cc66;">)</span></span><span class="sy0">;</span>
  <span class="kw1"><span style="color: #a1a100;">while</span></span> <span class="br0"><span style="color: #66cc66;">(</span></span><span class="sy0">!</span><span class="kw3"><span style="color: #000066;">feof</span></span><span class="br0"><span style="color: #66cc66;">(</span></span><span class="re0">$fp</span><span style="color: #66cc66;"><span class="br0">)</span><span class="br0">)</span></span> <span class="br0"><span style="color: #66cc66;">{</span></span>
    <span class="re0">$d</span> <span class="sy0">.=</span> <span class="kw3"><span style="color: #000066;">fgets</span></span><span class="br0"><span style="color: #66cc66;">(</span></span><span class="re0">$fp</span><span class="sy0">,</span> 4096<span class="br0"><span style="color: #66cc66;">)</span></span><span class="sy0">;</span>
  <span class="br0"><span style="color: #66cc66;">}</span></span>
?
  <span class="kw3"><span style="color: #000066;">fclose</span></span><span class="br0"><span style="color: #66cc66;">(</span></span><span class="re0">$fp</span><span class="br0"><span style="color: #66cc66;">)</span></span><span class="sy0">;</span>
  <span class="kw1"><span style="color: #a1a100;">echo</span></span> <span class="re0">$d</span><span class="sy0">;</span>
<span class="br0"><span style="color: #66cc66;">}</span></span>
<span class="sy1">?></span>

同样地,让我们来执行这个测试脚本

<span class="sy0">@</span>php <span class="sy0">/</span>phpinput_xmlrcp.php
HTTP/1.1 200 OK
Date: Thu, 08 Apr 2010 03:47:18 GMT
Server: Apache/2.2.3 (CentOS)
X-Powered-By: PHP/5.1.6
Content-Length: 154
Connection: close
Content-Type: text/html; charset=UTF-8

-------$_POST------------------
array(0) {
}

-------php://input-------------
<strong><?xml version="1.0">
<methodcall>
   <name>jt_userinfo</name>
</methodcall></strong>

执行这个脚本的时候,我们通过ngrep抓取的http请求数据包如下

T 192.168.0.8:45570 -> 192.168.0.6:80 [AP]
  <strong>POST</strong> /phpinput_server.php HTTP/1.1..
  Host: 192.168.0.6..<strong>Content-Type: text/html</strong>..Content-Length: 75..Connec
  tion: close....<strong><?xml version="1.0">.<methodcall>.   <name>jt_userinfo.</name></methodcall></strong>....

同样,我样也可以很容易地发现:
1,http请求中的Content-Type是text/xml。它表示http请求中的body数据是xml数据格式。
2,服务端$_POST打印出来的是一个空数组,即与http entity body不一致了。这跟上个例子不一样了,这里的Content-Type是text/xml,而不是application/x-www-form-urlencoded
3,而php://input数据还是跟http entity body数据一致。也就是php://input数据和$_POST数据不一致了。

我们再来看看通过GET方法提交表单数据的情况,php://input能不能读取到GET方法的表单数据?在这里,我们稍加改动一下phpinput_server.php文件,将$_POST改成$_GET。

<div class="codesnip-container">
<pre class='brush:php;toolbar:false;'><span class="kw2"><strong><?php</strong></span>
<span class="co1"><span style="color: #808080;">//@file phpinput_server.php</span></span>
<span class="re0">$raw_post_data</span> <span class="sy0">=</span> <span class="kw3"><span style="color: #000066;">file_get_contents</span></span><span class="br0"><span style="color: #66cc66;">(</span></span><span class="st_h">'php://input'</span><span class="sy0">,</span> <span class="st_h">'r'</span><span class="br0"><span style="color: #66cc66;">)</span></span><span class="sy0">;</span>
<span class="kw1"><span style="color: #a1a100;">echo</span></span> <span class="st0"><span style="color: #ff0000;">"-------<span class="es1">\$</span>_GET------------------<span class="es1">\n</span>"</span></span><span class="sy0">;</span>
<span class="kw1"><span style="color: #a1a100;">echo</span></span> <span class="kw3"><span style="color: #000066;">var_dump</span></span><span class="br0"><span style="color: #66cc66;">(</span></span><span class="re0">$_GET</span><span class="br0"><span style="color: #66cc66;">)</span></span> <span class="sy0">.</span> <span class="st0"><span style="color: #ff0000;">"<span class="es1">\n</span>"</span></span><span class="sy0">;</span>
<span class="kw1"><span style="color: #a1a100;">echo</span></span> <span class="st0"><span style="color: #ff0000;">"-------php://input-------------<span class="es1">\n</span>"</span></span><span class="sy0">;</span>
<span class="kw1"><span style="color: #a1a100;">echo</span></span> <span class="re0">$raw_post_data</span> <span class="sy0">.</span> <span class="st0"><span style="color: #ff0000;">"<span class="es1">\n</span>"</span></span><span class="sy0">;</span>
<span class="sy1">?></span>
?
<span class="kw2"><strong><?php</strong></span>
<span class="co1"><span style="color: #808080;">//@file phpinput_get.php</span></span>
<span class="re0">$query_path</span> <span class="sy0">=</span> <span class="st_h">'n='</span> <span class="sy0">.</span> <span class="kw3"><span style="color: #000066;">urldecode</span></span><span class="br0"><span style="color: #66cc66;">(</span></span><span class="st_h">'perfgeeks'</span><span class="br0"><span style="color: #66cc66;">)</span></span> <span class="sy0">.</span> <span class="st_h">'&p='</span> <span class="sy0">.</span> <span class="kw3"><span style="color: #000066;">urldecode</span></span><span class="br0"><span style="color: #66cc66;">(</span></span><span class="st_h">'7788'</span><span class="br0"><span style="color: #66cc66;">)</span></span><span class="sy0">;</span>
<span class="re0">$host</span> <span class="sy0">=</span> <span class="st_h">'192.168.0.6'</span><span class="sy0">;</span>
<span class="re0">$port</span> <span class="sy0">=</span> <span class="nu0"><span style="color: #ff33ff;">80</span></span><span class="sy0">;</span>
<span class="re0">$path</span> <span class="sy0">=</span> <span class="st_h">'/phpinput_server.php'</span><span class="sy0">;</span>
<span class="re0">$d</span> <span class="sy0">=</span> <span class="st_h">''</span><span class="sy0">;</span>
<span class="re0">$fp</span> <span class="sy0">=</span> <span class="kw3"><span style="color: #000066;">fsockopen</span></span><span class="br0"><span style="color: #66cc66;">(</span></span><span class="re0">$host</span><span class="sy0">,</span> <span class="re0">$port</span><span class="sy0">,</span> <span class="re0">$error_no</span><span class="sy0">,</span> <span class="re0">$error_desc</span><span class="sy0">,</span> 30<span class="br0"><span style="color: #66cc66;">)</span></span><span class="sy0">;</span>
<span class="kw1"><span style="color: #a1a100;">if</span></span> <span class="br0"><span style="color: #66cc66;">(</span></span><span class="re0">$fp</span><span class="br0"><span style="color: #66cc66;">)</span></span> <span class="br0"><span style="color: #66cc66;">{</span></span>
  <span class="kw3"><span style="color: #000066;">fputs</span></span><span class="br0"><span style="color: #66cc66;">(</span></span><span class="re0">$fp</span><span class="sy0">,</span> <span class="st0"><span style="color: #ff0000;">"GET <span class="es4">{$path}</span>?<span class="es4">{$query_path}</span> HTTP/1.1<span class="es1">\r</span><span class="es1">\n</span>"</span></span><span class="br0"><span style="color: #66cc66;">)</span></span><span class="sy0">;</span>
  <span class="kw3"><span style="color: #000066;">fputs</span></span><span class="br0"><span style="color: #66cc66;">(</span></span><span class="re0">$fp</span><span class="sy0">,</span> <span class="st0"><span style="color: #ff0000;">"Host: <span class="es4">{$host}</span><span class="es1">\r</span><span class="es1">\n</span>"</span></span><span class="br0"><span style="color: #66cc66;">)</span></span><span class="sy0">;</span>
  <span class="kw3"><span style="color: #000066;">fputs</span></span><span class="br0"><span style="color: #66cc66;">(</span></span><span class="re0">$fp</span><span class="sy0">,</span> <span class="st0"><span style="color: #ff0000;">"Connection: close<span class="es1">\r</span><span class="es1">\n</span><span class="es1">\r</span><span class="es1">\n</span>"</span></span><span class="br0"><span style="color: #66cc66;">)</span></span><span class="sy0">;</span>
?
  <span class="kw1"><span style="color: #a1a100;">while</span></span> <span class="br0"><span style="color: #66cc66;">(</span></span><span class="sy0">!</span><span class="kw3"><span style="color: #000066;">feof</span></span><span class="br0"><span style="color: #66cc66;">(</span></span><span class="re0">$fp</span><span style="color: #66cc66;"><span class="br0">)</span><span class="br0">)</span></span> <span class="br0"><span style="color: #66cc66;">{</span></span>
    <span class="re0">$d</span> <span class="sy0">.=</span> <span class="kw3"><span style="color: #000066;">fgets</span></span><span class="br0"><span style="color: #66cc66;">(</span></span><span class="re0">$fp</span><span class="sy0">,</span> 4096<span class="br0"><span style="color: #66cc66;">)</span></span><span class="sy0">;</span>
  <span class="br0"><span style="color: #66cc66;">}</span></span>
  <span class="kw3"><span style="color: #000066;">fclose</span></span><span class="br0"><span style="color: #66cc66;">(</span></span><span class="re0">$fp</span><span class="br0"><span style="color: #66cc66;">)</span></span><span class="sy0">;</span>
  <span class="kw1"><span style="color: #a1a100;">echo</span></span> <span class="re0">$d</span><span class="sy0">;</span>
 <span class="br0"><span style="color: #66cc66;">}</span></span>
<span class="sy1">?></span>

同样,我们执行下一phpinput_get.php测试脚本,它模拟了一个通常情况下的GET方法提交表单数据。

<span class="sy0">@</span>php <span class="sy0">/</span>phpinput_get.php
HTTP/1.1 200 OK
Date: Thu, 08 Apr 2010 07:38:15 GMT
Server: Apache/2.2.3 (CentOS)
X-Powered-By: PHP/5.1.6
Content-Length: 141
Connection: close
Content-Type: text/html; charset=UTF-8

-------$_GET------------------
array(2) {
  ["n"]=>
  string(9) "perfgeeks"
  ["p"]=>
  string(4) "7788"
}

-------php://input-------------

在这个时候,使用ngrep工具,捕获的相应的http请求数据包如下

T 192.168.0.8:36775 -> 192.168.0.6:80 [AP]
  <strong>GET</strong> /phpinput_server.php?<strong>n=perfgeeks&p=7788</strong> HTTP/1.1..
  Host: 192.168.0.6..Connection: close....

比较POST方法提交的http请求,通常GET方法提交的请求中,entity body为空。同时,不会指定Content-Type和Content-Length。但是,如果强硬数据http entity body,并指明正确地Content-Type和Content-Length,那么php://input还可是读取得到http entity body数据,但不是$_GET数据。

所根据,上面几个探测,我们可以作出以下总结:
1,Content-Type取值为application/x-www-form-urlencoded时,php会将http请求body相应数据会填入到数组$_POST,填入到$_POST数组中的数据是进行urldecode()解析的结果。(其实,除了该Content-Type,还有multipart/form-data表示数据是表单数据,稍后我们介绍)
2,php://input数据,只要Content-Type不为multipart/form-data(该条件限制稍后会介绍)。那么php://input数据与http entity body部分数据是一致的。该部分相一致的数据的长度由Content-Length指定。
3,仅当Content-Type为application/x-www-form-urlencoded且提交方法是POST方法时,$_POST数据与php://input数据才是”一致”(打上引号,表示它们格式不一致,内容一致)的。其它情况,它们都不一致。
4,php://input读取不到$_GET数据。是因为$_GET数据作为query_path写在http请求头部(header)的PATH字段,而不是写在http请求的body部分。

这也帮助我们理解了,为什么xml_rpc服务端读取数据都是通过file_get_contents(‘php://input’, ‘r’)。而不是从$_POST中读取,正是因为xml_rpc数据规格是xml,它的Content-Type是text/xml。

php://input碰到了multipart/form-data

上传文件的时候,表单的写法是这样的

<div class="codesnip-container">
<pre class='brush:php;toolbar:false;'><span class="sc2"><<span class="kw2"><strong><span style="color: #000000;">form</span></strong></span> <span class="kw3"><span style="color: #000066;">enctype</span></span><span class="sy0">=</span><span class="st0"><span style="color: #ff0000;">"multipart/form-data"</span></span> <span class="kw3"><span style="color: #000066;">action</span></span><span class="sy0">=</span><span class="st0"><span style="color: #ff0000;">"phpinput_server.php"</span></span> <span class="kw3"><span style="color: #000066;">method</span></span><span class="sy0">=</span><span class="st0"><span style="color: #ff0000;">"POST"</span></span> ></span>
    <span class="sc2"><<span class="kw2"><strong><span style="color: #000000;">input</span></strong></span> <span class="kw3"><span style="color: #000066;">type</span></span><span class="sy0">=</span><span class="st0"><span style="color: #ff0000;">"text"</span></span> <span class="kw3"><span style="color: #000066;">name</span></span><span class="sy0">=</span><span class="st0"><span style="color: #ff0000;">"n"</span></span>  <span class="sy0">/</span>></span>
    <span class="sc2"><<span class="kw2"><strong><span style="color: #000000;">input</span></strong></span> <span class="kw3"><span style="color: #000066;">type</span></span><span class="sy0">=</span><span class="st0"><span style="color: #ff0000;">"file"</span></span> <span class="kw3"><span style="color: #000066;">name</span></span><span class="sy0">=</span><span class="st0"><span style="color: #ff0000;">"f"</span></span> <span class="sy0">/</span>></span>
    <span class="sc2"><<span class="kw2"><strong><span style="color: #000000;">input</span></strong></span> <span class="kw3"><span style="color: #000066;">type</span></span><span class="sy0">=</span><span class="st0"><span style="color: #ff0000;">"submit"</span></span> <span class="kw3"><span style="color: #000066;">value</span></span><span class="sy0">=</span><span class="st0"><span style="color: #ff0000;">"upload now"</span></span> <span class="sy0">/</span>></span>
<span class="sc2"><<span class="sy0">/</span><span class="kw2"><strong><span style="color: #000000;">form</span></strong></span>></span>

那么,enctype=multipart/form-data这里的意义,就是将该次http请求头部(head)中的Content-Type设置为multipart/form-data。请查阅RFC1867对它的描述。multipart/form-data也表示以POST方法提交表单数据,它还伴随了文件上传,所以会跟application/x-www-form-urlencoded数据格式不一样。它会以一更种更合理的,更高效的数据格式传递给服务端。我们提交该表单数据,并且打印出响应结果,如下:

-------$_POST------------------
array(1) { ["n"]=> string(9) "perfgeeks" }
-------php://input-------------

同时,我们通过ngrep抓取的相应的http请求数据包如下:

########
T 192.168.0.8:3981 -> 192.168.0.6:80 [AP]
 <strong> POST</strong> /phpinput_server.php HTTP/1.1..Host: 192.168.0.6..Connection: kee
  p-alive..User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US) A
  ppleWebKit/533.2 (KHTML, like Gecko) Chrome/5.0.342.3 Safari/533.2..Re
  ferer: http://192.168.0.6/phpinput_server.php..Content-Length: 306..Ca
  che-Control: max-age=0..Origin: http://192.168.0.6..<strong>Content-Type: mult
  ipart/form-data; boundary=----WebKitFormBoundarybLQwkp4opIEZn1fA</strong>..Acce
  pt: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q
  =0.8,image/png,*/*;q=0.5..Accept-Encoding: gzip,deflate,sdch..Accept-L
  anguage: zh-CN,zh;q=0.8..Accept-Charset: GBK,utf-8;q=0.7,*;q=0.3..Cook
  ie: SESS3b0e658f87cf58240de13ab43a399df6=lju6o5bg8u04lv1ojugm2ccic6...
  .
##
T 192.168.0.8:3981 -> 192.168.0.6:80 [AP]
  ------WebKitFormBoundarybLQwkp4opIEZn1fA..Content-Disposition: form-da
  ta; <strong>name="n"....perfgeeks</strong>..------WebKitFormBoundarybLQwkp4opIEZn1fA..C
  ontent-Disposition: form-data; <strong>name="f"; filename="test.txt"..Content-
  Type: text/plain....i am file</strong>..multipart/form-data..------WebKitFormBo
  undarybLQwkp4opIEZn1fA--..
##

从响应输出来比对,$_POST数据跟请求提交数据相符,即$_POST = array(‘n’ => ‘perfgeeks’)。这也跟http请求body中的数据相呼应,同时说明PHP把相应的数据填入$_POST全局变量。而php://input输出为空,没有输出任何东西,尽管http请求数据包中body不为空。这表示,当Content-Type为multipart/form-data的时候,即便http请求body中存在数据,php://input也为空,PHP此时,不会把数据填入php://input流。所以,可以确定: php://input不能用于读取enctype=multipart/form-data数据。

我们再比较这次通过ngrep抓取的http请求数据包,我们会发现,最大不同的一点是Content-Type后面跟了boundary定义了数据的分界符,bounday是随机生成的。另外一个大不一样的,就是http entity body中的数据组织结构不一样了。

上一节,我们概述了,当Content-Type为application/x-www-form-urlencoded时,php://input和$_POST数据是“一致”的,为其它Content-Type的时候,php://input和$_POST数据数据是不一致的。因为只有在Content-Type为application/x-www-form-urlencoded或者为multipart/form-data的时候,PHP才会将http请求数据包中的body相应部分数据填入$_POST全局变量中,其它情况PHP都忽略。而php://input除了在数据类型为multipart/form-data之外为空外,其它情况都可能不为空。通过这一节,我们更加明白了php://input与$_POST的区别与联系。所以,再次确认,php://input无法读取enctype=multipart/form-data数据,当php://input遇到它时,永远为空,即便http entity body有数据。

php://input VS $http_raw_post_data

相信大家对php://input已经有一定深度地了解了。那么$http_raw_post_data是什么呢?$http_raw_post_data是PHP内置的一个全局变量。它用于,PHP在无法识别的Content-Type的情况下,将POST过来的数据原样地填入变量$http_raw_post_data。它同样无法读取Content-Type为multipart/form-data的POST数据。需要设置php.ini中的always_populate_raw_post_data值为On,PHP才会总把POST数据填入变量$http_raw_post_data。

把脚本phpinput_server.php改变一下,可以验证上述内容

<div class="codesnip-container">
<pre class='brush:php;toolbar:false;'><span class="kw2"><strong><?php</strong></span>
<span class="re0">$raw_post_data</span> <span class="sy0">=</span> <span class="kw3"><span style="color: #000066;">file_get_contents</span></span><span class="br0"><span style="color: #66cc66;">(</span></span><span class="st_h">'php://input'</span><span class="sy0">,</span> <span class="st_h">'r'</span><span class="br0"><span style="color: #66cc66;">)</span></span><span class="sy0">;</span>
<span class="re0">$rtn</span> <span class="sy0">=</span> <span class="br0"><span style="color: #66cc66;">(</span></span><span class="re0">$raw_post_data</span> <span class="sy0">==</span> <span class="re0">$HTTP_RAW_POST_DATA</span><span class="br0"><span style="color: #66cc66;">)</span></span> ? 1 <span class="sy0">:</span> <span class="nu0"><span style="color: #ff33ff;">0</span></span><span class="sy0">;</span>
<span class="kw1"><span style="color: #a1a100;">echo</span></span> <span class="re0">$rtn</span><span class="sy0">;</span>
<span class="sy1">?></span>

执行测试脚本

<span class="sy0">@</span>php phpinput_post.php
<span class="sy0">@</span>php phpinput_get.php
<span class="sy0">@</span>php phpinput_xmlrpc.php

得出的结果输出都是一样的,即都为1,表示php://input和$HTTP_RAW_POST_DATA是相同的。至于对内存的压力,我们这里就不做细致地测试了。有兴趣的,可以通过xhprof进行测试和观察。

以此,我们这节可以总结如下:
1, php://input 可以读取http entity body中指定长度的值,由Content-Length指定长度,不管是POST方式或者GET方法提交过来的数据。但是,一般GET方法提交数据时,http request entity body部分都为空。
2,php://input 与$HTTP_RAW_POST_DATA读取的数据是一样的,都只读取Content-Type不为multipart/form-data的数据。

学习笔记

1,Coentent-Type仅在取值为application/x-www-data-urlencoded和multipart/form-data两种情况下,PHP才会将http请求数据包中相应的数据填入全局变量$_POST
2,PHP不能识别的Content-Type类型的时候,会将http请求包中相应的数据填入变量$HTTP_RAW_POST_DATA
3, ?只有Coentent-Type不为multipart/form-data的时候,PHP不会将http请求数据包中的相应数据填入php://input,否则其它情况都会。填入的长度,由Coentent-Length指定。
4,只有Content-Type为application/x-www-data-urlencoded时,php://input数据才跟$_POST数据相一致。
5,php://input数据总是跟$HTTP_RAW_POST_DATA相同,但是php://input比$HTTP_RAW_POST_DATA更凑效,且不需要特殊设置php.ini
6,PHP会将PATH字段的query_path部分,填入全局变量$_GET。通常情况下,GET方法提交的http请求,body为空。

声明
本文内容由网友自发贡献,版权归原作者所有,本站不承担相应法律责任。如您发现有涉嫌抄袭侵权的内容,请联系admin@php.cn
超越炒作:评估当今PHP的角色超越炒作:评估当今PHP的角色Apr 12, 2025 am 12:17 AM

PHP在现代编程中仍然是一个强大且广泛使用的工具,尤其在web开发领域。1)PHP易用且与数据库集成无缝,是许多开发者的首选。2)它支持动态内容生成和面向对象编程,适合快速创建和维护网站。3)PHP的性能可以通过缓存和优化数据库查询来提升,其广泛的社区和丰富生态系统使其在当今技术栈中仍具重要地位。

PHP中的弱参考是什么?什么时候有用?PHP中的弱参考是什么?什么时候有用?Apr 12, 2025 am 12:13 AM

在PHP中,弱引用是通过WeakReference类实现的,不会阻止垃圾回收器回收对象。弱引用适用于缓存系统和事件监听器等场景,需注意其不能保证对象存活,且垃圾回收可能延迟。

解释PHP中的__ Invoke Magic方法。解释PHP中的__ Invoke Magic方法。Apr 12, 2025 am 12:07 AM

\_\_invoke方法允许对象像函数一样被调用。1.定义\_\_invoke方法使对象可被调用。2.使用$obj(...)语法时,PHP会执行\_\_invoke方法。3.适用于日志记录和计算器等场景,提高代码灵活性和可读性。

解释PHP 8.1中的纤维以进行并发。解释PHP 8.1中的纤维以进行并发。Apr 12, 2025 am 12:05 AM

Fibers在PHP8.1中引入,提升了并发处理能力。1)Fibers是一种轻量级的并发模型,类似于协程。2)它们允许开发者手动控制任务的执行流,适合处理I/O密集型任务。3)使用Fibers可以编写更高效、响应性更强的代码。

PHP社区:资源,支持和发展PHP社区:资源,支持和发展Apr 12, 2025 am 12:04 AM

PHP社区提供了丰富的资源和支持,帮助开发者成长。1)资源包括官方文档、教程、博客和开源项目如Laravel和Symfony。2)支持可以通过StackOverflow、Reddit和Slack频道获得。3)开发动态可以通过关注RFC了解。4)融入社区可以通过积极参与、贡献代码和学习分享来实现。

PHP与Python:了解差异PHP与Python:了解差异Apr 11, 2025 am 12:15 AM

PHP和Python各有优势,选择应基于项目需求。1.PHP适合web开发,语法简单,执行效率高。2.Python适用于数据科学和机器学习,语法简洁,库丰富。

php:死亡还是简单地适应?php:死亡还是简单地适应?Apr 11, 2025 am 12:13 AM

PHP不是在消亡,而是在不断适应和进化。1)PHP从1994年起经历多次版本迭代,适应新技术趋势。2)目前广泛应用于电子商务、内容管理系统等领域。3)PHP8引入JIT编译器等功能,提升性能和现代化。4)使用OPcache和遵循PSR-12标准可优化性能和代码质量。

PHP的未来:改编和创新PHP的未来:改编和创新Apr 11, 2025 am 12:01 AM

PHP的未来将通过适应新技术趋势和引入创新特性来实现:1)适应云计算、容器化和微服务架构,支持Docker和Kubernetes;2)引入JIT编译器和枚举类型,提升性能和数据处理效率;3)持续优化性能和推广最佳实践。

See all articles

热AI工具

Undresser.AI Undress

Undresser.AI Undress

人工智能驱动的应用程序,用于创建逼真的裸体照片

AI Clothes Remover

AI Clothes Remover

用于从照片中去除衣服的在线人工智能工具。

Undress AI Tool

Undress AI Tool

免费脱衣服图片

Clothoff.io

Clothoff.io

AI脱衣机

AI Hentai Generator

AI Hentai Generator

免费生成ai无尽的。

热门文章

R.E.P.O.能量晶体解释及其做什么(黄色晶体)
3 周前By尊渡假赌尊渡假赌尊渡假赌
R.E.P.O.最佳图形设置
3 周前By尊渡假赌尊渡假赌尊渡假赌
R.E.P.O.如果您听不到任何人,如何修复音频
3 周前By尊渡假赌尊渡假赌尊渡假赌
WWE 2K25:如何解锁Myrise中的所有内容
4 周前By尊渡假赌尊渡假赌尊渡假赌

热工具

SublimeText3 Linux新版

SublimeText3 Linux新版

SublimeText3 Linux最新版

DVWA

DVWA

Damn Vulnerable Web App (DVWA) 是一个PHP/MySQL的Web应用程序,非常容易受到攻击。它的主要目标是成为安全专业人员在合法环境中测试自己的技能和工具的辅助工具,帮助Web开发人员更好地理解保护Web应用程序的过程,并帮助教师/学生在课堂环境中教授/学习Web应用程序安全。DVWA的目标是通过简单直接的界面练习一些最常见的Web漏洞,难度各不相同。请注意,该软件中

ZendStudio 13.5.1 Mac

ZendStudio 13.5.1 Mac

功能强大的PHP集成开发环境

SecLists

SecLists

SecLists是最终安全测试人员的伙伴。它是一个包含各种类型列表的集合,这些列表在安全评估过程中经常使用,都在一个地方。SecLists通过方便地提供安全测试人员可能需要的所有列表,帮助提高安全测试的效率和生产力。列表类型包括用户名、密码、URL、模糊测试有效载荷、敏感数据模式、Web shell等等。测试人员只需将此存储库拉到新的测试机上,他就可以访问到所需的每种类型的列表。

SublimeText3汉化版

SublimeText3汉化版

中文版,非常好用