<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "https://www.w3.org/Bugs/Public/page.cgi?id=bugzilla.dtd">

<bugzilla version="5.0.4"
          urlbase="https://www.w3.org/Bugs/Public/"
          
          maintainer="sysbot+bugzilla@w3.org"
>

    <bug>
          <bug_id>852</bug_id>
          
          <creation_ts>2004-08-31 14:42:37 +0000</creation_ts>
          <short_desc>&amp;PHPSESSID in urls</short_desc>
          <delta_ts>2005-01-22 15:24:11 +0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>Validator</product>
          <component>check</component>
          <version>0.7.0</version>
          <rep_platform>All</rep_platform>
          <op_sys>other</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>INVALID</resolution>
          
          
          <bug_file_loc></bug_file_loc>
          <status_whiteboard></status_whiteboard>
          <keywords></keywords>
          <priority>P1</priority>
          <bug_severity>critical</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          <everconfirmed>1</everconfirmed>
          <reporter name="Venimus">venimus</reporter>
          <assigned_to name="Terje Bless">link</assigned_to>
          
          
          <qa_contact name="qa-dev tracking">www-validator-cvs</qa_contact>

      

      

      

          <comment_sort_order>oldest_to_newest</comment_sort_order>  
          <long_desc isprivate="0" >
    <commentid>2176</commentid>
    <comment_count>0</comment_count>
    <who name="Venimus">venimus</who>
    <bug_when>2004-08-31 14:42:37 +0000</bug_when>
    <thetext>PHP automatically adds &amp;PHPSESSID at the end of the url&apos;s if cookies are not 
supported. This prevents sites from validating. While this doesn&apos;t appear on 
normal browser it does for the validator page. I think &amp;PHPSESSID should be 
ignored while parsing.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>2179</commentid>
    <comment_count>1</comment_count>
    <who name="David Dorward">david</who>
    <bug_when>2004-08-31 15:38:03 +0000</bug_when>
    <thetext>It is an error in the markup and, as such, should not be ignored.

PHP adds query string variables to URLs in documents when sessions are enabled.
By default it generates code that is invalid under every version of (X)HTML. The
PHP manual describes how to configure the system to use correctly escaped
ampersands (although it only mentions XHTML).

This should be considered a bug in PHP (as it is used in the default configuration).</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>2181</commentid>
    <comment_count>2</comment_count>
    <who name="Venimus">venimus</who>
    <bug_when>2004-08-31 21:44:08 +0000</bug_when>
    <thetext>Of course it can be reconfigured. But how do you suggest escaping when the 
configuration file is not accessible (while it usualy isn&apos;t)?</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>2182</commentid>
    <comment_count>3</comment_count>
    <who name="Olivier Thereaux">ot</who>
    <bug_when>2004-08-31 22:58:23 +0000</bug_when>
    <thetext>Don&apos;t shoot the messenger... 

If PHP generates, by default, broken markup and most people cannot change this (wrong) setting, PHP 
is broken and should be fixed.

This has nothing to do with the validator.

In other words, your question about &quot;how to escape when the configuration file is not accessible&quot; would 
be best asked to the php developers, not here. </thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>2872</commentid>
    <comment_count>4</comment_count>
    <who name="Cool Dude 2k">CoolDude2k</who>
    <bug_when>2005-01-22 15:24:11 +0000</bug_when>
    <thetext>ini_set(&quot;arg_separator.output&quot;,&quot;&amp;amp;&quot;);(In reply to comment #0)
&gt; PHP automatically adds &amp;PHPSESSID at the end of the url&apos;s if cookies are not 
&gt; supported. This prevents sites from validating. While this doesn&apos;t appear on 
&gt; normal browser it does for the validator page. I think &amp;PHPSESSID should be 
&gt; ignored while parsing.

ini_set(&quot;arg_separator.output&quot;,&quot;&amp;amp;&quot;);
I use this and it fixs it for me.</thetext>
  </long_desc>
      
      

    </bug>

</bugzilla>