HTTP: send associative extra headers correctly

Both request drivers assume $extra_headers is a flat list of
"Name: value" strings, but callers pass an associative array. The most
visible case is the CardDAV provider, which sends

    array('Content-Type' => 'text/vcard; charset=utf-8')

from RainLoop\Providers\AddressBook\CardDAV::davClientRequest().

curl: CURLOPT_HTTPHEADER receives the map as-is, so curl emits the bare
value "text/vcard; charset=utf-8" as a header line and discards it as
malformed.

socket: array_merge() then implode("\r\n", ...) keeps only the values,
producing the same malformed line.

In both drivers the header is therefore lost, and because a body is
present the request falls back to Content-Type:
application/x-www-form-urlencoded. A CardDAV server is entitled to reject
that: Cyrus IMAP answers PUT of a vCard with

    403 <C:supported-address-data/>

so every contact upload fails while the download half of the sync works,
which makes the sync look silently one-way.

Normalise string keys to "Name: value" in both drivers and leave integer
keys untouched, so existing callers that already pass a flat list are
unaffected.
This commit is contained in:
Fathi Ben Nasr 2026-08-12 13:10:40 +00:00
parent c154d23cfe
commit a761a838d5
2 changed files with 14 additions and 2 deletions

View file

@ -47,7 +47,14 @@ class CURL extends \SnappyMail\HTTP\Request
\curl_setopt($c, CURLOPT_CAINFO, $this->ca_bundle); \curl_setopt($c, CURLOPT_CAINFO, $this->ca_bundle);
} }
if ($extra_headers) { if ($extra_headers) {
\curl_setopt($c, CURLOPT_HTTPHEADER, $extra_headers); // CURLOPT_HTTPHEADER expects a flat list of "Name: value" strings.
// Callers may pass an associative array, in which case curl sends
// the bare values as malformed header lines and drops them.
$aHeaderLines = array();
foreach ($extra_headers as $mKey => $sValue) {
$aHeaderLines[] = \is_int($mKey) ? $sValue : "{$mKey}: {$sValue}";
}
\curl_setopt($c, CURLOPT_HTTPHEADER, $aHeaderLines);
} }
if ($this->auth['user'] && $this->auth['type']) { if ($this->auth['user'] && $this->auth['type']) {
if ($this->auth['type'] & self::AUTH_BEARER ) { if ($this->auth['type'] & self::AUTH_BEARER ) {

View file

@ -43,7 +43,12 @@ class Socket extends \SnappyMail\HTTP\Request
$extra_headers['Authorization'] = static::$Authorization[$host]; $extra_headers['Authorization'] = static::$Authorization[$host];
} }
if ($extra_headers) { if ($extra_headers) {
$headers = \array_merge($headers, $extra_headers); // $headers is a flat list of "Name: value" strings, so an
// associative $extra_headers would lose its keys in the implode()
// below and emit bare values as malformed header lines.
foreach ($extra_headers as $mKey => $sValue) {
$headers[] = \is_int($mKey) ? $sValue : "{$mKey}: {$sValue}";
}
} }
$headers = \implode("\r\n", $headers); $headers = \implode("\r\n", $headers);
if (!\is_null($body)) { if (!\is_null($body)) {