Skip to content

Phalcon Http

Updated View as Markdown

Http\Cookie

ClassSource on GitHub

Provide OO wrappers to manage a HTTP cookie.

Uses Phalcon\Contracts\Http\HttpTypes · Phalcon\Di\AbstractInjectionAware · Phalcon\Di\DiInterface · Phalcon\Encryption\Crypt\CryptInterface · Phalcon\Filter\FilterInterface · Phalcon\Http\Cookie\CookieInterface · Phalcon\Http\Cookie\Exception · Phalcon\Http\Cookie\Exceptions\CookieKeyTooShort · Phalcon\Http\Cookie\Exceptions\CryptInterfaceRequired · Phalcon\Http\Cookie\Exceptions\CryptServiceUnavailable · Phalcon\Http\Cookie\Exceptions\FilterServiceUnavailable · Phalcon\Http\Response\Exception · Phalcon\Http\Traits\EncryptionAwareTrait · Phalcon\Session\ManagerInterface · Phalcon\Traits\Support\Helper\Arr\GetTrait · Stringable

Method Summary

public__construct(string$name,mixed$value = null,int$expire = 0,string$path = "/",bool$secure = false,string$domain = "",bool$httpOnly = false,array$options = [])Phalcon\Http\Cookie constructor.publicstring__toString()Magic __toString method converts the cookie's value to stringpublicvoiddelete()Deletes the cookie by setting an expiration time in the pastpublicstringgetDomain()Returns the domain that the cookie is available topublicintgetExpiration()Returns the current expiration timepublicboolgetHttpOnly()Returns if the cookie is accessible only through the HTTP protocolpublicstringgetName()Returns the current cookie's namepublicarraygetOptions()Returns the current cookie's optionspublicstringgetPath()Returns the current cookie's pathpublicboolgetSecure()Returns whether the cookie must only be sent when the connection ispublicmixedgetValue(mixed$filters = null,mixed$defaultValue = null)Returns the cookie's value.publicCookieInterfacerestore()Reads the cookie-related info from the SESSION to restore the cookie aspublicCookieInterfacesend()Sends the cookie to the HTTP client.publicCookieInterfacesetDomain( string$domain )Sets the domain that the cookie is available topublicCookieInterfacesetExpiration( int$expire )Sets the cookie's expiration timepublicCookieInterfacesetHttpOnly( bool$httpOnly )Sets if the cookie is accessible only through the HTTP protocolpublicCookieInterfacesetOptions( array$options )Sets the cookie's optionspublicCookieInterfacesetPath( string$path )Sets the cookie's pathpublicCookieInterfacesetSecure( bool$secure )Sets if the cookie must only be sent when the connection is securepublicCookieInterfacesetSignKey( string|null$signKey = null )Sets the cookie's sign key.publicCookieInterfacesetValue( mixed$value )Sets the cookie's valuepublicCookieInterfaceuseEncryption( bool$useEncryption )Sets if the cookie must be encrypted/decrypted automaticallyprotectedvoidassertSignKeyIsLongEnough( string$signKey )Assert the cookie's key is enough long.

Properties

protectedstring$domain = ""
protectedint$expire = 0
protectedFilterInterface|null$filter = null
protectedbool$httpOnly = false
protectedbool$isRead = false
protectedbool$isRestored = false
protectedstring$name
protectedarray$options = []
protectedstring$path = "/"
protectedbool$secure = false
protectedstring|null$signKey = nullThe cookie's sign key.
protectedmixed$value = null

Methods

Public · 22

__construct()

public function __construct(
    string $name,
    mixed $value = null,
    int $expire = 0,
    string $path = "/",
    bool $secure = false,
    string $domain = "",
    bool $httpOnly = false,
    array $options = []
);

Phalcon\Http\Cookie constructor.

__toString()

public function __toString(): string;

Magic __toString method converts the cookie’s value to string

delete()

public function delete(): void;

Deletes the cookie by setting an expiration time in the past

getDomain()

public function getDomain(): string;

Returns the domain that the cookie is available to

getExpiration()

public function getExpiration(): int;

Returns the current expiration time

getHttpOnly()

public function getHttpOnly(): bool;

Returns if the cookie is accessible only through the HTTP protocol

getName()

public function getName(): string;

Returns the current cookie’s name

getOptions()

public function getOptions(): array;

Returns the current cookie’s options

getPath()

public function getPath(): string;

Returns the current cookie’s path

getSecure()

public function getSecure(): bool;

Returns whether the cookie must only be sent when the connection is secure (HTTPS)

getValue()

public function getValue(
    mixed $filters = null,
    mixed $defaultValue = null
): mixed;

Returns the cookie’s value.

@todo filters needs to be array/string

restore()

public function restore(): CookieInterface;

Reads the cookie-related info from the SESSION to restore the cookie as it was set.

This method is automatically called internally so normally you don’t need to call it.

send()

public function send(): CookieInterface;

Sends the cookie to the HTTP client.

Stores the cookie definition in session.

setDomain()

public function setDomain( string $domain ): CookieInterface;

Sets the domain that the cookie is available to

setExpiration()

public function setExpiration( int $expire ): CookieInterface;

Sets the cookie’s expiration time

setHttpOnly()

public function setHttpOnly( bool $httpOnly ): CookieInterface;

Sets if the cookie is accessible only through the HTTP protocol

setOptions()

public function setOptions( array $options ): CookieInterface;

Sets the cookie’s options

setPath()

public function setPath( string $path ): CookieInterface;

Sets the cookie’s path

setSecure()

public function setSecure( bool $secure ): CookieInterface;

Sets if the cookie must only be sent when the connection is secure (HTTPS)

setSignKey()

public function setSignKey( string|null $signKey = null ): CookieInterface;

Sets the cookie’s sign key.

The `$signKey’ MUST be at least 32 characters long and generated using a cryptographically secure pseudo random generator.

Use NULL to disable cookie signing.

@see \Phalcon\Encryption\Security\Random

setValue()

public function setValue( mixed $value ): CookieInterface;

Sets the cookie’s value

useEncryption()

public function useEncryption( bool $useEncryption ): CookieInterface;

Sets if the cookie must be encrypted/decrypted automatically

Protected · 1

assertSignKeyIsLongEnough()

protected function assertSignKeyIsLongEnough( string $signKey ): void;

Assert the cookie’s key is enough long.

Http\Cookie\CookieInterface

InterfaceSource on GitHub

Interface for Phalcon\Http\Cookie

  • Phalcon\Http\Cookie\CookieInterface

Uses Phalcon\Contracts\Http\HttpTypes

Method Summary

Methods

Public · 19

delete()

public function delete(): void;

Deletes the cookie

getDomain()

public function getDomain(): string;

Returns the domain that the cookie is available to

getExpiration()

public function getExpiration(): int;

Returns the current expiration time

getHttpOnly()

public function getHttpOnly(): bool;

Returns if the cookie is accessible only through the HTTP protocol

getName()

public function getName(): string;

Returns the current cookie’s name

getOptions()

public function getOptions(): array;

Returns the current cookie’s options

getPath()

public function getPath(): string;

Returns the current cookie’s path

getSecure()

public function getSecure(): bool;

Returns whether the cookie must only be sent when the connection is secure (HTTPS)

getValue()

public function getValue(
    mixed $filters = null,
    mixed $defaultValue = null
): mixed;

Returns the cookie’s value.

@todo check if $filters can be more type specific

isUsingEncryption()

public function isUsingEncryption(): bool;

Check if the cookie is using implicit encryption

send()

public function send(): CookieInterface;

Sends the cookie to the HTTP client

setDomain()

public function setDomain( string $domain ): CookieInterface;

Sets the domain that the cookie is available to

setExpiration()

public function setExpiration( int $expire ): CookieInterface;

Sets the cookie’s expiration time

setHttpOnly()

public function setHttpOnly( bool $httpOnly ): CookieInterface;

Sets if the cookie is accessible only through the HTTP protocol

setOptions()

public function setOptions( array $options ): CookieInterface;

Sets the cookie’s options

setPath()

public function setPath( string $path ): CookieInterface;

Sets the cookie’s expiration time

setSecure()

public function setSecure( bool $secure ): CookieInterface;

Sets if the cookie must only be sent when the connection is secure (HTTPS)

setValue()

public function setValue( mixed $value ): CookieInterface;

Sets the cookie’s value

@todo check if we can make this a string

useEncryption()

public function useEncryption( bool $useEncryption ): CookieInterface;

Sets if the cookie must be encrypted/decrypted automatically

Http\Cookie\Exception

ClassSource on GitHub

Phalcon\Http\Cookie\Exception

Exceptions thrown in Phalcon\Http\Cookie will use this class.

Http\Cookie\Exceptions\CookieKeyTooShort

ClassSource on GitHub

Uses Phalcon\Http\Cookie\Exception

Method Summary

Methods

Public · 1

__construct()

public function __construct( int $length );

Http\Cookie\Exceptions\CryptInterfaceRequired

ClassSource on GitHub

Uses Phalcon\Http\Cookie\Exception

Method Summary

Methods

Public · 1

__construct()

public function __construct();

Http\Cookie\Exceptions\CryptServiceUnavailable

ClassSource on GitHub

Uses Phalcon\Http\Cookie\Exception

Method Summary

Methods

Public · 1

__construct()

public function __construct();

Http\Cookie\Exceptions\FilterServiceUnavailable

ClassSource on GitHub

Uses Phalcon\Http\Cookie\Exception

Method Summary

Methods

Public · 1

__construct()

public function __construct();

Http\Message\RequestMethodInterface

InterfaceSource on GitHub

Interface for Request methods

Implementation of this file has been influenced by PHP FIG @link https://github.com/php-fig/http-message-util/ @license https://github.com/php-fig/http-message-util/blob/master/LICENSE

  • Phalcon\Http\Message\RequestMethodInterface

Constants

stringMETHOD_CONNECT = "CONNECT"
stringMETHOD_DELETE = "DELETE"
stringMETHOD_GET = "GET"
stringMETHOD_HEAD = "HEAD"
stringMETHOD_OPTIONS = "OPTIONS"
stringMETHOD_PATCH = "PATCH"
stringMETHOD_POST = "POST"
stringMETHOD_PURGE = "PURGE"
stringMETHOD_PUT = "PUT"
stringMETHOD_TRACE = "TRACE"

Http\Message\ResponseStatusCodeInterface

InterfaceSource on GitHub

Interface for Request methods

Implementation of this file has been influenced by PHP FIG @link https://github.com/php-fig/http-message-util/ @license https://github.com/php-fig/http-message-util/blob/master/LICENSE

Defines constants for common HTTP status code.

@see https://tools.ietf.org/html/rfc2295#section-8.1 @see https://tools.ietf.org/html/rfc2324#section-2.3 @see https://tools.ietf.org/html/rfc2518#section-9.7 @see https://tools.ietf.org/html/rfc2774#section-7 @see https://tools.ietf.org/html/rfc3229#section-10.4 @see https://tools.ietf.org/html/rfc4918#section-11 @see https://tools.ietf.org/html/rfc5842#section-7.1 @see https://tools.ietf.org/html/rfc5842#section-7.2 @see https://tools.ietf.org/html/rfc6585#section-3 @see https://tools.ietf.org/html/rfc6585#section-4 @see https://tools.ietf.org/html/rfc6585#section-5 @see https://tools.ietf.org/html/rfc6585#section-6 @see https://tools.ietf.org/html/rfc7231#section-6 @see https://tools.ietf.org/html/rfc7238#section-3 @see https://tools.ietf.org/html/rfc7725#section-3 @see https://tools.ietf.org/html/rfc7540#section-9.1.2 @see https://tools.ietf.org/html/rfc8297#section-2 @see https://tools.ietf.org/html/rfc8470#section-7

  • Phalcon\Http\Message\ResponseStatusCodeInterface

Constants

intSTATUS_ACCEPTED = 202
intSTATUS_ALREADY_REPORTED = 208
intSTATUS_BAD_GATEWAY = 502
intSTATUS_BAD_REQUEST = 400
intSTATUS_BANDWIDTH_LIMIT_EXCEEDED = 509
intSTATUS_BLOCKED_BY_WINDOWS_PARENTAL_CONTROLS = 450
intSTATUS_CLIENT_CLOSED_REQUEST = 499
intSTATUS_CONFLICT = 409
intSTATUS_CONNECTION_TIMEOUT = 522
intSTATUS_CONTINUE = 100
intSTATUS_CREATED = 201
intSTATUS_EARLY_HINTS = 103
intSTATUS_EXPECTATION_FAILED = 417
intSTATUS_FAILED_DEPENDENCY = 424
intSTATUS_FORBIDDEN = 403
intSTATUS_FOUND = 302
intSTATUS_GATEWAY_TIMEOUT = 504
intSTATUS_GONE = 410
intSTATUS_HTTP_REQUEST_SENT_TO_HTTPS_PORT = 497
intSTATUS_IM_A_TEAPOT = 418
intSTATUS_IM_USED = 226
intSTATUS_INSUFFICIENT_STORAGE = 507
intSTATUS_INTERNAL_SERVER_ERROR = 500
intSTATUS_INVALID_SSL_CERTIFICATE = 526
intSTATUS_INVALID_TOKEN_ESRI = 498
intSTATUS_LENGTH_REQUIRED = 411
intSTATUS_LOCKED = 423
intSTATUS_LOGIN_TIMEOUT = 440
intSTATUS_LOOP_DETECTED = 508
intSTATUS_METHOD_FAILURE = 420
intSTATUS_METHOD_NOT_ALLOWED = 405
intSTATUS_MISDIRECTED_REQUEST = 421
intSTATUS_MOVED_PERMANENTLY = 301
intSTATUS_MULTIPLE_CHOICES = 300
intSTATUS_MULTI_STATUS = 207
intSTATUS_NETWORK_AUTHENTICATION_REQUIRED = 511
intSTATUS_NETWORK_CONNECT_TIMEOUT_ERROR = 599
intSTATUS_NETWORK_READ_TIMEOUT_ERROR = 598
intSTATUS_NON_AUTHORITATIVE_INFORMATION = 203
intSTATUS_NOT_ACCEPTABLE = 406
intSTATUS_NOT_EXTENDED = 510
intSTATUS_NOT_FOUND = 404
intSTATUS_NOT_IMPLEMENTED = 501
intSTATUS_NOT_MODIFIED = 304
intSTATUS_NO_CONTENT = 204
intSTATUS_NO_RESPONSE = 444
intSTATUS_OK = 200
intSTATUS_ORIGIN_DNS_ERROR = 530
intSTATUS_ORIGIN_IS_UNREACHABLE = 523
intSTATUS_PAGE_EXPIRED = 419
intSTATUS_PARTIAL_CONTENT = 206
intSTATUS_PAYLOAD_TOO_LARGE = 413
intSTATUS_PAYMENT_REQUIRED = 402
intSTATUS_PERMANENT_REDIRECT = 308
intSTATUS_PRECONDITION_FAILED = 412
intSTATUS_PRECONDITION_REQUIRED = 428
intSTATUS_PROCESSING = 102
intSTATUS_PROXY_AUTHENTICATION_REQUIRED = 407
intSTATUS_RAILGUN_ERROR = 527
intSTATUS_RANGE_NOT_SATISFIABLE = 416
intSTATUS_REQUEST_HEADER_FIELDS_TOO_LARGE = 431
intSTATUS_REQUEST_HEADER_TOO_LARGE = 494
intSTATUS_REQUEST_TIMEOUT = 408
intSTATUS_RESERVED = 306
intSTATUS_RESET_CONTENT = 205
intSTATUS_RETRY_WITH = 449
intSTATUS_SEE_OTHER = 303
intSTATUS_SERVICE_UNAVAILABLE = 503
intSTATUS_SSL_CERTIFICATE_ERROR = 495
intSTATUS_SSL_CERTIFICATE_REQUIRED = 496
intSTATUS_SSL_HANDSHAKE_FAILED = 525
intSTATUS_SWITCHING_PROTOCOLS = 101
intSTATUS_TEMPORARY_REDIRECT = 307
intSTATUS_THIS_IS_FINE = 218
intSTATUS_TIMEOUT_OCCURRED = 524
intSTATUS_TOO_EARLY = 425
intSTATUS_TOO_MANY_REQUESTS = 429
intSTATUS_UNAUTHORIZED = 401
intSTATUS_UNAVAILABLE_FOR_LEGAL_REASONS = 451
intSTATUS_UNKNOWN_ERROR = 520
intSTATUS_UNPROCESSABLE_ENTITY = 422
intSTATUS_UNSUPPORTED_MEDIA_TYPE = 415
intSTATUS_UPGRADE_REQUIRED = 426
intSTATUS_URI_TOO_LONG = 414
intSTATUS_USE_PROXY = 305
intSTATUS_VARIANT_ALSO_NEGOTIATES = 506
intSTATUS_VERSION_NOT_SUPPORTED = 505
intSTATUS_WEB_SERVER_IS_DOWN = 521

Http\Request

ClassSource on GitHub

Encapsulates request information for easy and secure access from application controllers.

The request object is a simple value object that is passed between the dispatcher and controller classes. It packages the HTTP request environment.

use Phalcon\Http\Request;

$request = new Request();

if ($request->isPost() && $request->isAjax()) {
    echo "Request was made using POST and AJAX";
}

// Retrieve SERVER variables
$request->getServer("HTTP_HOST");

// GET, POST, PUT, DELETE, HEAD, OPTIONS, PATCH, PURGE, TRACE, CONNECT
$request->getMethod();

// An array of languages the client accepts
$request->getLanguages();

Uses Phalcon\Contracts\Http\AttributeRequest · Phalcon\Contracts\Http\HttpTypes · Phalcon\Di\AbstractInjectionAware · Phalcon\Di\DiInterface · Phalcon\Events\ManagerInterface · Phalcon\Events\Traits\EventsAwareTrait · Phalcon\Filter\FilterInterface · Phalcon\Http\Message\RequestMethodInterface · Phalcon\Http\Request\Bag\AttributeBag · Phalcon\Http\Request\Exception · Phalcon\Http\Request\Exceptions\FilterServiceUnavailable · Phalcon\Http\Request\Exceptions\InvalidHost · Phalcon\Http\Request\Exceptions\InvalidHttpMethod · Phalcon\Http\Request\Exceptions\MissingFilters · Phalcon\Http\Request\Exceptions\SanitizerNotFound · Phalcon\Http\Request\File · Phalcon\Http\Request\FileInterface · Phalcon\Support\Helper\Json\Decode · Phalcon\Traits\Php\FileTrait · stdClass

Method Summary

publicmixedget(string|null$name = null,mixed$filters = null,mixed$defaultValue = null,bool$notAllowEmpty = false,bool$noRecursive = false)Gets a variable from the $_REQUEST superglobal applying filters ifpublicarraygetAcceptableContent()Gets an array with mime/types and their quality accepted by thepublicAttributeBaggetAttributes()Returns the request attributes bag. Attributes are arbitrary,publicarray|nullgetBasicAuth()Gets auth info accepted by the browser/client frompublicstringgetBestAccept()Gets best mime/type accepted by the browser/client frompublicstringgetBestCharset()Gets best charset accepted by the browser/client frompublicstringgetBestLanguage()Gets the best language accepted by the browser/client frompublicstring|boolgetClientAddress( bool$trustForwardedHeader = false )Gets most possible client IP Address. This method searches inpublicarraygetClientCharsets()Gets a charsets array and their quality accepted by the browser/clientpublicstring|nullgetContentType()Gets content type which request has been madepublicarraygetDigestAuth()Gets auth info accepted by the browser/client frompublicmixedgetFilteredData(string$methodKey,string$method,string|null$name = null,mixed$defaultValue = null,bool$notAllowEmpty = false,bool$noRecursive = false)Gets filtered datapublicmixedgetFilteredPatch(string|null$name = null,mixed$defaultValue = null,bool$notAllowEmpty = false,bool$noRecursive = false)Retrieves a patch value always sanitized with the preset filterspublicmixedgetFilteredPost(string|null$name = null,mixed$defaultValue = null,bool$notAllowEmpty = false,bool$noRecursive = false)Retrieves a post value always sanitized with the preset filterspublicmixedgetFilteredPut(string|null$name = null,mixed$defaultValue = null,bool$notAllowEmpty = false,bool$noRecursive = false)Retrieves a put value always sanitized with the preset filterspublicmixedgetFilteredQuery(string|null$name = null,mixed$defaultValue = null,bool$notAllowEmpty = false,bool$noRecursive = false)Retrieves a query/get value always sanitized with the preset filterspublicstringgetHTTPReferer()Gets web page that refers active request. ie: http://www.google.compublicstringgetHeader( string$header )Gets HTTP header from request datapublicarraygetHeaders()Returns the available headers in the requestpublicstringgetHttpHost()Gets host name used by the request.publicboolgetHttpMethodParameterOverride()Return the HTTP method parameter override flagpublic\stdClass|array|boolgetJsonRawBody( bool$associative = false )Gets decoded JSON HTTP raw request bodypublicarraygetLanguages()Gets languages array and their quality accepted by the browser/clientpublicstringgetMethod()Gets HTTP method which request has been madepublicmixedgetPatch(string|null$name = null,mixed$filters = null,mixed$defaultValue = null,bool$notAllowEmpty = false,bool$noRecursive = false)Gets a variable from put requestpublicintgetPort()Gets information about the port on which the request is made.publicmixedgetPost(string|null$name = null,mixed$filters = null,mixed$defaultValue = null,bool$notAllowEmpty = false,bool$noRecursive = false)Gets a variable from the $_POST superglobal applying filters if neededpublicstringgetPreferredIsoLocaleVariant()Gets the preferred ISO locale variant.publicmixedgetPut(string|null$name = null,mixed$filters = null,mixed$defaultValue = null,bool$notAllowEmpty = false,bool$noRecursive = false)Gets a variable from the PUT requestpublicmixedgetQuery(string|null$name = null,mixed$filters = null,mixed$defaultValue = null,bool$notAllowEmpty = false,bool$noRecursive = false)Gets variable from $_GET superglobal applying filters if needed.publicstringgetRawBody()Gets HTTP raw request bodypublicstringgetScheme()Gets HTTP schema (http/https)publicstring|nullgetServer( string$name )Gets variable from $_SERVER superglobalpublicstringgetServerAddress()Gets active server address IPpublicstringgetServerName()Gets active server namepublicstringgetURI( bool$onlyPath = false )Gets HTTP URI which request has been made topublicFileInterface[]getUploadedFiles(bool$onlySuccessful = false,bool$namedKeys = false)Gets attached files as Phalcon\Http\Request\File instancespublicstringgetUserAgent()Gets HTTP user agent used to make the requestpublicboolhas( string$name )Checks whether $_REQUEST superglobal has certain indexpublicboolhasFiles()Returns if the request has files or notpublicboolhasHeader( string$header )Checks whether headers has certain indexpublicboolhasPatch( string$name )Checks whether the PATCH data has certain indexpublicboolhasPost( string$name )Checks whether $_POST superglobal has certain indexpublicboolhasPut( string$name )Checks whether the PUT data has certain indexpublicboolhasQuery( string$name )Checks whether $_GET superglobal has certain indexpublicboolhasServer( string$name )Checks whether $_SERVER superglobal has certain indexpublicboolisAjax()Checks whether request has been made using ajaxpublicboolisConnect()Checks whether HTTP method is CONNECT.publicboolisDelete()Checks whether HTTP method is DELETE.publicboolisGet()Checks whether HTTP method is GET.publicboolisHead()Checks whether HTTP method is HEAD.publicboolisJson()Checks whether request content type contains json datapublicboolisMethod(mixed$methods,bool$strict = false)Check if HTTP method match any of the passed methodspublicboolisOptions()Checks whether HTTP method is OPTIONS.publicboolisPatch()Checks whether HTTP method is PATCH.publicboolisPost()Checks whether HTTP method is POST.publicboolisPurge()Checks whether HTTP method is PURGE (Squid and Varnish support).publicboolisPut()Checks whether HTTP method is PUT.publicboolisSecure()Checks whether request has been made using any secure layerpublicboolisSoap()Checks whether request has been made using SOAPpublicboolisStrictHostCheck()Checks if the Request::getHttpHost method will be use strict validationpublicboolisTrace()Checks whether HTTP method is TRACE.publicboolisValidHttpMethod( string$method )Checks if a method is a valid HTTP methodpublicintnumFiles( bool$onlySuccessful = false )Returns the number of files availablepublicstaticsetHttpMethodParameterOverride( bool$override )Set the HTTP method parameter override flagpublicstaticsetParameterFilters(string$name,array$filters = [],array$scope = [])Sets automatic sanitizers/filters for a particular field and forpublicstaticsetStrictHostCheck( bool$flag = true )Sets if the Request::getHttpHost method must be use strict validationpublicstaticsetTrustedProxies( array$trustedProxies )Set a trusted proxy list for X-Forwarded-For headerpublicstaticsetTrustedProxyHeader( string$trustedProxyHeader )This header takes priority when parsing HTTP headersprotectedstringgetBestQuality(array$qualityParts,string$name)Process a request header and return the one with best qualityprotectedmixedgetHelper(array$source,string|null$name = null,mixed$filters = null,mixed$defaultValue = null,bool$notAllowEmpty = false,bool$noRecursive = false)Helper to get data from superglobals, applying filters if needed.protectedarraygetQualityHeader(string$serverIndex,string$name)Process a request header and return an array of values with theirprotectedinthasFileHelper(mixed$data,bool$onlySuccessful)Recursively counts file in an array of filesprotectedboolisIpAddressInCIDR(string$ip,string$cidr)Check if an IP address exists in CIDR rangeprotectedarrayresolveAuthorizationHeaders()Resolve authorization headers.protectedarraysmoothFiles(array$names,array$types,array$tmp_names,array$sizes,array$errors,string$prefix)Smooth out $_FILES to have plain array with all files uploaded

Properties

protectedAttributeBag|null$attributes = null
protectedFilterInterface|null$filterService = null
protectedbool$methodOverride = false
protectedarray|null$postCache = null
protectedarray$queryFilters = []
protectedstring$rawBody = ""
protectedbool$strictHostCheck = false
protectedarray$trustedProxies = []
protectedstring$trustedProxyHeader = ""

Methods

Public · 69

get()

public function get(
    string|null $name = null,
    mixed $filters = null,
    mixed $defaultValue = null,
    bool $notAllowEmpty = false,
    bool $noRecursive = false
): mixed;

Gets a variable from the $_REQUEST superglobal applying filters if needed. If no parameters are given the $_REQUEST superglobal is returned

// Returns value from $_REQUEST["user_email"] without sanitizing
$userEmail = $request->get("user_email");

// Returns value from $_REQUEST["user_email"] with sanitizing
$userEmail = $request->get("user_email", "email");

@todo check the filters

getAcceptableContent()

public function getAcceptableContent(): array;

Gets an array with mime/types and their quality accepted by the browser/client from _SERVER[“HTTP_ACCEPT”]

getAttributes()

public function getAttributes(): AttributeBag;

Returns the request attributes bag. Attributes are arbitrary, application-defined values attached to the request during its lifecycle (router, dispatcher, security components etc.). The bag is created empty on first access and the same instance is returned on every subsequent call.

$request->getAttributes()->set("user", $user);

$user = $request->getAttributes()->get("user");

getBasicAuth()

public function getBasicAuth(): array|null;

Gets auth info accepted by the browser/client from $_SERVER[“PHP_AUTH_USER”]

getBestAccept()

public function getBestAccept(): string;

Gets best mime/type accepted by the browser/client from _SERVER[“HTTP_ACCEPT”]

getBestCharset()

public function getBestCharset(): string;

Gets best charset accepted by the browser/client from _SERVER[“HTTP_ACCEPT_CHARSET”]

getBestLanguage()

public function getBestLanguage(): string;

Gets the best language accepted by the browser/client from _SERVER[“HTTP_ACCEPT_LANGUAGE”]

getClientAddress()

public function getClientAddress( bool $trustForwardedHeader = false ): string|bool;

Gets most possible client IP Address. This method searches in $_SERVER["REMOTE_ADDR"] and optionally in $_SERVER["HTTP_X_FORWARDED_FOR"] and returns the first non-private or non-reserved IP address

The user provided trusted header takes priority before checking X-Forwarded-For header.

Using trusted proxies list, user has to provide a trusted list of proxy IPs

$request
    ->setTrustedProxies($trustedProxies)
    ->getClientAddress(true);

Using user provided trusted header, header should only ever contain 1 IP address, eg. HTTP_CLIENT_IP

$request
    ->setTrustedProxyHeader('HTTP_CLIENT_IP')
    ->setTrustedProxies($trustedProxies)
    ->getClientAddress(true);

getClientCharsets()

public function getClientCharsets(): array;

Gets a charsets array and their quality accepted by the browser/client from _SERVER[“HTTP_ACCEPT_CHARSET”]

getContentType()

public function getContentType(): string|null;

Gets content type which request has been made

getDigestAuth()

public function getDigestAuth(): array;

Gets auth info accepted by the browser/client from $_SERVER[“PHP_AUTH_DIGEST”]

getFilteredData()

public function getFilteredData(
    string $methodKey,
    string $method,
    string|null $name = null,
    mixed $defaultValue = null,
    bool $notAllowEmpty = false,
    bool $noRecursive = false
): mixed;

Gets filtered data

getFilteredPatch()

public function getFilteredPatch(
    string|null $name = null,
    mixed $defaultValue = null,
    bool $notAllowEmpty = false,
    bool $noRecursive = false
): mixed;

Retrieves a patch value always sanitized with the preset filters

getFilteredPost()

public function getFilteredPost(
    string|null $name = null,
    mixed $defaultValue = null,
    bool $notAllowEmpty = false,
    bool $noRecursive = false
): mixed;

Retrieves a post value always sanitized with the preset filters

getFilteredPut()

public function getFilteredPut(
    string|null $name = null,
    mixed $defaultValue = null,
    bool $notAllowEmpty = false,
    bool $noRecursive = false
): mixed;

Retrieves a put value always sanitized with the preset filters

getFilteredQuery()

public function getFilteredQuery(
    string|null $name = null,
    mixed $defaultValue = null,
    bool $notAllowEmpty = false,
    bool $noRecursive = false
): mixed;

Retrieves a query/get value always sanitized with the preset filters

getHTTPReferer()

public function getHTTPReferer(): string;

Gets web page that refers active request. ie: http://www.google.com

getHeader()

public function getHeader( string $header ): string;

Gets HTTP header from request data

getHeaders()

public function getHeaders(): array;

Returns the available headers in the request

$_SERVER = [
    "PHP_AUTH_USER" => "phalcon",
    "PHP_AUTH_PW"   => "secret",
];

$headers = $request->getHeaders();

echo $headers["Authorization"]; // Basic cGhhbGNvbjpzZWNyZXQ=

getHttpHost()

public function getHttpHost(): string;

Gets host name used by the request.

Request::getHttpHost trying to find host name in following order:

  • $_SERVER["HTTP_HOST"]
  • $_SERVER["SERVER_NAME"]
  • $_SERVER["SERVER_ADDR"]

Optionally Request::getHttpHost validates and clean host name. The Request::$strictHostCheck can be used to validate host name.

Note: validation and cleaning have a negative performance impact because they use regular expressions.

use Phalcon\Http\Request;

$request = new Request;

$_SERVER["HTTP_HOST"] = "example.com";
$request->getHttpHost(); // example.com

$_SERVER["HTTP_HOST"] = "example.com:8080";
$request->getHttpHost(); // example.com:8080

$request->setStrictHostCheck(true);
$_SERVER["HTTP_HOST"] = "ex=am~ple.com";
$request->getHttpHost(); // UnexpectedValueException

$_SERVER["HTTP_HOST"] = "ExAmPlE.com";
$request->getHttpHost(); // example.com

getHttpMethodParameterOverride()

public function getHttpMethodParameterOverride(): bool;

Return the HTTP method parameter override flag

getJsonRawBody()

public function getJsonRawBody( bool $associative = false ): \stdClass|array|bool;

Gets decoded JSON HTTP raw request body

getLanguages()

public function getLanguages(): array;

Gets languages array and their quality accepted by the browser/client from _SERVER[“HTTP_ACCEPT_LANGUAGE”]

getMethod()

public function getMethod(): string;

Gets HTTP method which request has been made

If the X-HTTP-Method-Override header is set, and if the method is a POST, then it is used to determine the “real” intended HTTP method.

The _method request parameter can also be used to determine the HTTP method, but only if setHttpMethodParameterOverride(true) has been called.

The method is always an uppercased string.

getPatch()

public function getPatch(
    string|null $name = null,
    mixed $filters = null,
    mixed $defaultValue = null,
    bool $notAllowEmpty = false,
    bool $noRecursive = false
): mixed;

Gets a variable from put request

// Returns value from $_PATCH["user_email"] without sanitizing
$userEmail = $request->getPatch("user_email");

// Returns value from $_PATCH["user_email"] with sanitizing
$userEmail = $request->getPatch("user_email", "email");

getPort()

public function getPort(): int;

Gets information about the port on which the request is made.

getPost()

public function getPost(
    string|null $name = null,
    mixed $filters = null,
    mixed $defaultValue = null,
    bool $notAllowEmpty = false,
    bool $noRecursive = false
): mixed;

Gets a variable from the $_POST superglobal applying filters if needed If no parameters are given the $_POST superglobal is returned

// Returns value from $_POST["user_email"] without sanitizing
$userEmail = $request->getPost("user_email");

// Returns value from $_POST["user_email"] with sanitizing
$userEmail = $request->getPost("user_email", "email");

getPreferredIsoLocaleVariant()

public function getPreferredIsoLocaleVariant(): string;

Gets the preferred ISO locale variant.

Gets the preferred locale accepted by the client from the “Accept-Language” request HTTP header and returns the base part of it i.e. en instead of en-US.

Note: This method relies on the $_SERVER["HTTP_ACCEPT_LANGUAGE"] header.

@link https://www.iso.org/standard/50707.html

getPut()

public function getPut(
    string|null $name = null,
    mixed $filters = null,
    mixed $defaultValue = null,
    bool $notAllowEmpty = false,
    bool $noRecursive = false
): mixed;

Gets a variable from the PUT request

// Returns value from PUT stream without sanitizing
$userEmail = $request->getPut("user_email");

// Returns value from PUT stream with sanitizing
$userEmail = $request->getPut("user_email", "email");

getQuery()

public function getQuery(
    string|null $name = null,
    mixed $filters = null,
    mixed $defaultValue = null,
    bool $notAllowEmpty = false,
    bool $noRecursive = false
): mixed;

Gets variable from $_GET superglobal applying filters if needed. If no parameters are given the $_GET superglobal is returned

// Returns value from $_GET["id"] without sanitizing
$id = $request->getQuery("id");

// Returns value from $_GET["id"] with sanitizing
$id = $request->getQuery("id", "int");

// Returns value from $_GET["id"] with a default value
$id = $request->getQuery("id", null, 150);

getRawBody()

public function getRawBody(): string;

Gets HTTP raw request body

getScheme()

public function getScheme(): string;

Gets HTTP schema (http/https)

getServer()

public function getServer( string $name ): string|null;

Gets variable from $_SERVER superglobal

getServerAddress()

public function getServerAddress(): string;

Gets active server address IP

getServerName()

public function getServerName(): string;

Gets active server name

getURI()

public function getURI( bool $onlyPath = false ): string;

Gets HTTP URI which request has been made to

// Returns /some/path?with=queryParams
$uri = $request->getURI();

// Returns /some/path
$uri = $request->getURI(true);

getUploadedFiles()

public function getUploadedFiles(
    bool $onlySuccessful = false,
    bool $namedKeys = false
): FileInterface[];

Gets attached files as Phalcon\Http\Request\File instances

getUserAgent()

public function getUserAgent(): string;

Gets HTTP user agent used to make the request

has()

public function has( string $name ): bool;

Checks whether $_REQUEST superglobal has certain index

hasFiles()

public function hasFiles(): bool;

Returns if the request has files or not

hasHeader()

final public function hasHeader( string $header ): bool;

Checks whether headers has certain index

hasPatch()

public function hasPatch( string $name ): bool;

Checks whether the PATCH data has certain index

hasPost()

public function hasPost( string $name ): bool;

Checks whether $_POST superglobal has certain index

hasPut()

public function hasPut( string $name ): bool;

Checks whether the PUT data has certain index

hasQuery()

public function hasQuery( string $name ): bool;

Checks whether $_GET superglobal has certain index

hasServer()

final public function hasServer( string $name ): bool;

Checks whether $_SERVER superglobal has certain index

isAjax()

public function isAjax(): bool;

Checks whether request has been made using ajax

isConnect()

public function isConnect(): bool;

Checks whether HTTP method is CONNECT. if _SERVER[“REQUEST_METHOD”]===“CONNECT”

isDelete()

public function isDelete(): bool;

Checks whether HTTP method is DELETE. if _SERVER[“REQUEST_METHOD”]===“DELETE”

isGet()

public function isGet(): bool;

Checks whether HTTP method is GET. if _SERVER[“REQUEST_METHOD”]===“GET”

isHead()

public function isHead(): bool;

Checks whether HTTP method is HEAD. if _SERVER[“REQUEST_METHOD”]===“HEAD”

isJson()

public function isJson(): bool;

Checks whether request content type contains json data

isMethod()

public function isMethod(
    mixed $methods,
    bool $strict = false
): bool;

Check if HTTP method match any of the passed methods When strict is true it checks if validated methods are real HTTP methods

@todo check the $methods type - refactor this !!

isOptions()

public function isOptions(): bool;

Checks whether HTTP method is OPTIONS. if _SERVER[“REQUEST_METHOD”]===“OPTIONS”

isPatch()

public function isPatch(): bool;

Checks whether HTTP method is PATCH. if _SERVER[“REQUEST_METHOD”]===“PATCH”

isPost()

public function isPost(): bool;

Checks whether HTTP method is POST. if _SERVER[“REQUEST_METHOD”]===“POST”

isPurge()

public function isPurge(): bool;

Checks whether HTTP method is PURGE (Squid and Varnish support). if _SERVER[“REQUEST_METHOD”]===“PURGE”

isPut()

public function isPut(): bool;

Checks whether HTTP method is PUT. if _SERVER[“REQUEST_METHOD”]===“PUT”

isSecure()

public function isSecure(): bool;

Checks whether request has been made using any secure layer

isSoap()

public function isSoap(): bool;

Checks whether request has been made using SOAP

isStrictHostCheck()

public function isStrictHostCheck(): bool;

Checks if the Request::getHttpHost method will be use strict validation of host name or not

isTrace()

public function isTrace(): bool;

Checks whether HTTP method is TRACE. if _SERVER[“REQUEST_METHOD”]===“TRACE”

isValidHttpMethod()

public function isValidHttpMethod( string $method ): bool;

Checks if a method is a valid HTTP method

numFiles()

public function numFiles( bool $onlySuccessful = false ): int;

Returns the number of files available

setHttpMethodParameterOverride()

public function setHttpMethodParameterOverride( bool $override ): static;

Set the HTTP method parameter override flag

setParameterFilters()

public function setParameterFilters(
    string $name,
    array $filters = [],
    array $scope = []
): static;

Sets automatic sanitizers/filters for a particular field and for particular methods

setStrictHostCheck()

public function setStrictHostCheck( bool $flag = true ): static;

Sets if the Request::getHttpHost method must be use strict validation of host name or not

setTrustedProxies()

public function setTrustedProxies( array $trustedProxies ): static;

Set a trusted proxy list for X-Forwarded-For header

setTrustedProxyHeader()

public function setTrustedProxyHeader( string $trustedProxyHeader ): static;

This header takes priority when parsing HTTP headers The header return only 1 single IP address, prefixed with HTTP_ eg. HTTP_CLIENT_IP.

Protected · 7

getBestQuality()

protected function getBestQuality(
    array $qualityParts,
    string $name
): string;

Process a request header and return the one with best quality

getHelper()

protected function getHelper(
    array $source,
    string|null $name = null,
    mixed $filters = null,
    mixed $defaultValue = null,
    bool $notAllowEmpty = false,
    bool $noRecursive = false
): mixed;

Helper to get data from superglobals, applying filters if needed. If no parameters are given the superglobal is returned.

getQualityHeader()

protected function getQualityHeader(
    string $serverIndex,
    string $name
): array;

Process a request header and return an array of values with their qualities

hasFileHelper()

protected function hasFileHelper(
    mixed $data,
    bool $onlySuccessful
): int;

Recursively counts file in an array of files

isIpAddressInCIDR()

protected function isIpAddressInCIDR(
    string $ip,
    string $cidr
): bool;

Check if an IP address exists in CIDR range

resolveAuthorizationHeaders()

protected function resolveAuthorizationHeaders(): array;

Resolve authorization headers.

smoothFiles()

protected function smoothFiles(
    array $names,
    array $types,
    array $tmp_names,
    array $sizes,
    array $errors,
    string $prefix
): array;

Smooth out $_FILES to have plain array with all files uploaded

Http\RequestInterface

InterfaceSource on GitHub

Interface for Phalcon\Http\Request

Uses Phalcon\Contracts\Http\HttpTypes · Phalcon\Http\Request\FileInterface · stdClass

Method Summary

publicmixedget(string|null$name = null,mixed$filters = null,mixed$defaultValue = null,bool$notAllowEmpty = false,bool$noRecursive = false)Gets a variable from the $_REQUEST superglobal applying filters ifpublicarraygetAcceptableContent()Return an array with mime/types and their quality accepted by thepublicarray|nullgetBasicAuth()Gets auth info accepted by the browser/client frompublicstringgetBestAccept()Return the best mime/type accepted by the browser/client frompublicstringgetBestCharset()Return the best charset accepted by the browser/client frompublicstringgetBestLanguage()Return the best language accepted by the browser/client frompublicstring|boolgetClientAddress( bool$trustForwardedHeader = false )Return the most possible client IPv4 Address. This method searches inpublicarraygetClientCharsets()Return a charset array and their quality accepted by the browser/clientpublicstring|nullgetContentType()Return the content type which request has been madepublicarraygetDigestAuth()Return the auth info accepted by the browser/client frompublicstringgetHTTPReferer()Return the web page that refers active request. ie: https://phalcon.iopublicstringgetHeader( string$header )Return the HTTP header from request datapublicarraygetHeaders()Returns the available headers in the requestpublicstringgetHttpHost()Return the host name used by the request.publicarray|bool|stdClassgetJsonRawBody( bool$associative = false )Return the decoded JSON HTTP raw request bodypublicarraygetLanguages()Return the languages array and their quality accepted by thepublicstringgetMethod()Return the HTTP method which request has been madepublicintgetPort()Return the information about the port on which the request is madepublicmixedgetPost(string|null$name = null,mixed$filters = null,mixed$defaultValue = null,bool$notAllowEmpty = false,bool$noRecursive = false)Return a variable from the $_POST superglobal applying filters if needed.publicmixedgetPut(string|null$name = null,mixed$filters = null,mixed$defaultValue = null,bool$notAllowEmpty = false,bool$noRecursive = false)Return a variable from put requestpublicmixedgetQuery(string|null$name = null,mixed$filters = null,mixed$defaultValue = null,bool$notAllowEmpty = false,bool$noRecursive = false)Return a variable from $_GET superglobal applying filters if needed.publicstringgetRawBody()Return the HTTP raw request bodypublicstringgetScheme()Return the HTTP schema (http/https)publicstring|nullgetServer( string$name )Return a variable from $_SERVER superglobalpublicstringgetServerAddress()Return the active server address IPpublicstringgetServerName()Return the active server namepublicstringgetURI( bool$onlyPath = false )Return the HTTP URI which request has been made topublicFileInterface[]getUploadedFiles(bool$onlySuccessful = false,bool$namedKeys = false)Return the attached files as Phalcon\Http\Request\FileInterfacepublicstringgetUserAgent()Return the HTTP user agent used to make the requestpublicboolhas( string$name )Return whether the $_REQUEST superglobal has certain indexpublicboolhasFiles()Return whether the request includes attached filespublicboolhasHeader( string$header )Return whether the headers have a certain indexpublicboolhasPost( string$name )Return whether the $_POST superglobal has certain indexpublicboolhasPut( string$name )Return whether the PUT data has certain indexpublicboolhasQuery( string$name )Return whether the $_GET superglobal has certain indexpublicboolhasServer( string$name )Return whether the $_SERVER superglobal has certain indexpublicboolisAjax()Return whether the request has been made using ajax. Checks ifpublicboolisConnect()Return whether the HTTP method is CONNECT. ifpublicboolisDelete()Return whether the HTTP method is DELETE. ifpublicboolisGet()Return whether the HTTP method is GET. ifpublicboolisHead()Return whether the HTTP method is HEAD. ifpublicboolisMethod(mixed$methods,bool$strict = false)Return if the current HTTP method matches any of the passed methodspublicboolisOptions()Return whether the HTTP method is OPTIONS. ifpublicboolisPost()Return whether the HTTP method is POST. ifpublicboolisPurge()Return whether the HTTP method is PURGE (Squid and Varnish support). ifpublicboolisPut()Return whether the HTTP method is PUT. ifpublicboolisSecure()Return whether the request has been made using any secure layerpublicboolisSoap()Return whether the request has been made using SOAPpublicboolisTrace()Return whether the HTTP method is TRACE.publicintnumFiles( bool$onlySuccessful = false )Returns the number of files available

Methods

Public · 50

get()

public function get(
    string|null $name = null,
    mixed $filters = null,
    mixed $defaultValue = null,
    bool $notAllowEmpty = false,
    bool $noRecursive = false
): mixed;

Gets a variable from the $_REQUEST superglobal applying filters if needed. If no parameters are given the $_REQUEST superglobal is returned

// Returns value from $_REQUEST["user_email"] without sanitizing
$userEmail = $request->get("user_email");

// Returns value from $_REQUEST["user_email"] with sanitizing
$userEmail = $request->get("user_email", "email");

@todo check the filters here

getAcceptableContent()

public function getAcceptableContent(): array;

Return an array with mime/types and their quality accepted by the browser/client from _SERVER[“HTTP_ACCEPT”]

getBasicAuth()

public function getBasicAuth(): array|null;

Gets auth info accepted by the browser/client from $_SERVER[“PHP_AUTH_USER”]

getBestAccept()

public function getBestAccept(): string;

Return the best mime/type accepted by the browser/client from _SERVER[“HTTP_ACCEPT”]

getBestCharset()

public function getBestCharset(): string;

Return the best charset accepted by the browser/client from _SERVER[“HTTP_ACCEPT_CHARSET”]

getBestLanguage()

public function getBestLanguage(): string;

Return the best language accepted by the browser/client from _SERVER[“HTTP_ACCEPT_LANGUAGE”]

getClientAddress()

public function getClientAddress( bool $trustForwardedHeader = false ): string|bool;

Return the most possible client IPv4 Address. This method searches in $_SERVER[“REMOTE_ADDR”] and optionally in $_SERVER[“HTTP_X_FORWARDED_FOR”]

getClientCharsets()

public function getClientCharsets(): array;

Return a charset array and their quality accepted by the browser/client from _SERVER[“HTTP_ACCEPT_CHARSET”]

getContentType()

public function getContentType(): string|null;

Return the content type which request has been made

getDigestAuth()

public function getDigestAuth(): array;

Return the auth info accepted by the browser/client from $_SERVER[“PHP_AUTH_DIGEST”]

getHTTPReferer()

public function getHTTPReferer(): string;

Return the web page that refers active request. ie: https://phalcon.io

getHeader()

public function getHeader( string $header ): string;

Return the HTTP header from request data

getHeaders()

public function getHeaders(): array;

Returns the available headers in the request

$_SERVER = [
    "PHP_AUTH_USER" => "phalcon",
    "PHP_AUTH_PW"   => "secret",
];

$headers = $request->getHeaders();

echo $headers["Authorization"]; // Basic cGhhbGNvbjpzZWNyZXQ=

getHttpHost()

public function getHttpHost(): string;

Return the host name used by the request.

Request::getHttpHost trying to find host name in following order:

  • $_SERVER["HTTP_HOST"]
  • $_SERVER["SERVER_NAME"]
  • $_SERVER["SERVER_ADDR"]

Optionally Request::getHttpHost validates and clean host name. The Request::$strictHostCheck can be used to validate host name.

Note: validation and cleaning have a negative performance impact because they use regular expressions.

use Phalcon\Http\Request;

$request = new Request;

$_SERVER["HTTP_HOST"] = "example.com";
$request->getHttpHost(); // example.com

$_SERVER["HTTP_HOST"] = "example.com:8080";
$request->getHttpHost(); // example.com:8080

$request->setStrictHostCheck(true);
$_SERVER["HTTP_HOST"] = "ex=am~ple.com";
$request->getHttpHost(); // UnexpectedValueException

$_SERVER["HTTP_HOST"] = "ExAmPlE.com";
$request->getHttpHost(); // example.com

getJsonRawBody()

public function getJsonRawBody( bool $associative = false ): array|bool|stdClass;

Return the decoded JSON HTTP raw request body

getLanguages()

public function getLanguages(): array;

Return the languages array and their quality accepted by the browser/client from _SERVER[“HTTP_ACCEPT_LANGUAGE”]

getMethod()

public function getMethod(): string;

Return the HTTP method which request has been made

If the X-HTTP-Method-Override header is set, and if the method is a POST, then it is used to determine the “real” intended HTTP method.

The _method request parameter can also be used to determine the HTTP method, but only if setHttpMethodParameterOverride(true) has been called.

The method is always an uppercased string.

getPort()

public function getPort(): int;

Return the information about the port on which the request is made

getPost()

public function getPost(
    string|null $name = null,
    mixed $filters = null,
    mixed $defaultValue = null,
    bool $notAllowEmpty = false,
    bool $noRecursive = false
): mixed;

Return a variable from the $_POST superglobal applying filters if needed. If no parameters are given the $_POST superglobal is returned

// Returns value from $_POST["user_email"] without sanitizing
$userEmail = $request->getPost("user_email");

// Returns value from $_POST["user_email"] with sanitizing
$userEmail = $request->getPost("user_email", "email");

@todo check the filters

getPut()

public function getPut(
    string|null $name = null,
    mixed $filters = null,
    mixed $defaultValue = null,
    bool $notAllowEmpty = false,
    bool $noRecursive = false
): mixed;

Return a variable from put request

// Returns value from PUT stream without sanitizing
$userEmail = $request->getPut("user_email");

// Returns value from PUT stream with sanitizing
$userEmail = $request->getPut("user_email", "email");

@todo check the filters

getQuery()

public function getQuery(
    string|null $name = null,
    mixed $filters = null,
    mixed $defaultValue = null,
    bool $notAllowEmpty = false,
    bool $noRecursive = false
): mixed;

Return a variable from $_GET superglobal applying filters if needed. If no parameters are given the $_GET superglobal is returned

// Returns value from $_GET["id"] without sanitizing
$id = $request->getQuery("id");

// Returns value from $_GET["id"] with sanitizing
$id = $request->getQuery("id", "int");

// Returns value from $_GET["id"] with a default value
$id = $request->getQuery("id", null, 150);

@todo check the filters

getRawBody()

public function getRawBody(): string;

Return the HTTP raw request body

getScheme()

public function getScheme(): string;

Return the HTTP schema (http/https)

getServer()

public function getServer( string $name ): string|null;

Return a variable from $_SERVER superglobal

getServerAddress()

public function getServerAddress(): string;

Return the active server address IP

getServerName()

public function getServerName(): string;

Return the active server name

getURI()

public function getURI( bool $onlyPath = false ): string;

Return the HTTP URI which request has been made to

// Returns /some/path?with=queryParams
$uri = $request->getURI();

// Returns /some/path
$uri = $request->getURI(true);

getUploadedFiles()

public function getUploadedFiles(
    bool $onlySuccessful = false,
    bool $namedKeys = false
): FileInterface[];

Return the attached files as Phalcon\Http\Request\FileInterface compatible instances

getUserAgent()

public function getUserAgent(): string;

Return the HTTP user agent used to make the request

has()

public function has( string $name ): bool;

Return whether the $_REQUEST superglobal has certain index

hasFiles()

public function hasFiles(): bool;

Return whether the request includes attached files

hasHeader()

public function hasHeader( string $header ): bool;

Return whether the headers have a certain index

hasPost()

public function hasPost( string $name ): bool;

Return whether the $_POST superglobal has certain index

hasPut()

public function hasPut( string $name ): bool;

Return whether the PUT data has certain index

hasQuery()

public function hasQuery( string $name ): bool;

Return whether the $_GET superglobal has certain index

hasServer()

public function hasServer( string $name ): bool;

Return whether the $_SERVER superglobal has certain index

isAjax()

public function isAjax(): bool;

Return whether the request has been made using ajax. Checks if $_SERVER[“HTTP_X_REQUESTED_WITH”] === “XMLHttpRequest”

isConnect()

public function isConnect(): bool;

Return whether the HTTP method is CONNECT. if $_SERVER[“REQUEST_METHOD”] === “CONNECT”

isDelete()

public function isDelete(): bool;

Return whether the HTTP method is DELETE. if $_SERVER[“REQUEST_METHOD”] === “DELETE”

isGet()

public function isGet(): bool;

Return whether the HTTP method is GET. if $_SERVER[“REQUEST_METHOD”] === “GET”

isHead()

public function isHead(): bool;

Return whether the HTTP method is HEAD. if $_SERVER[“REQUEST_METHOD”] === “HEAD”

isMethod()

public function isMethod(
    mixed $methods,
    bool $strict = false
): bool;

Return if the current HTTP method matches any of the passed methods

isOptions()

public function isOptions(): bool;

Return whether the HTTP method is OPTIONS. if $_SERVER[“REQUEST_METHOD”] === “OPTIONS”

isPost()

public function isPost(): bool;

Return whether the HTTP method is POST. if $_SERVER[“REQUEST_METHOD”] === “POST”

isPurge()

public function isPurge(): bool;

Return whether the HTTP method is PURGE (Squid and Varnish support). if $_SERVER[“REQUEST_METHOD”] === “PURGE”

isPut()

public function isPut(): bool;

Return whether the HTTP method is PUT. if $_SERVER[“REQUEST_METHOD”] === “PUT”

isSecure()

public function isSecure(): bool;

Return whether the request has been made using any secure layer

isSoap()

public function isSoap(): bool;

Return whether the request has been made using SOAP

isTrace()

public function isTrace(): bool;

Return whether the HTTP method is TRACE. if $_SERVER[“REQUEST_METHOD”] === “TRACE”

numFiles()

public function numFiles( bool $onlySuccessful = false ): int;

Returns the number of files available

Http\Request\Bag\AbstractBag

AbstractSource on GitHub

Shared base for the HTTP request bags. A bag is a string- or integer-keyed value store backed by a raw array, exposing get/has/set/remove/all plus typed readers for cast-with-default access.

Two protected hooks (normalizeKey, normalizeItems) let subclasses change key handling without restating the surface.

The ArrayAccess append form ($bag[] = $value) is rejected with a NullKeyException: the append form supplies no explicit key, so the write could never be addressed by the caller.

@implements ArrayAccess<int|string, mixed> @implements IteratorAggregate<int|string, mixed>

Uses ArrayAccess · ArrayIterator · Countable · IteratorAggregate · Phalcon\Contracts\Http\HttpTypes · Phalcon\Http\Request\Exceptions\NullKeyException · Traversable

Method Summary

public__construct( array$items = [] )AbstractBag constructor.publicarrayall()Returns all the elements of the bagpublicintcount()Returns the number of elements in the bagpublicmixedget(mixed$key,mixed$defaultValue = null)Returns an element of the bag, or the default value if it is not setpublicarraygetArray(mixed$key,array$defaultValue = [])Returns an element of the bag as an array. The default value ispublicboolgetBool(mixed$key,bool$defaultValue = false)Returns an element of the bag cast to bool, or the default value ifpublicfloatgetFloat(mixed$key,float$defaultValue = 0.0)Returns an element of the bag cast to float, or the default value ifpublicintgetInt(mixed$key,int$defaultValue = 0)Returns an element of the bag cast to int, or the default value ifpublicTraversablegetIterator()Returns the iterator of the bagpublicstringgetString(mixed$key,string$defaultValue = "")Returns an element of the bag cast to string, or the default value ifpublicboolhas( mixed$key )Checks whether an element exists in the bagpublicbooloffsetExists( mixed$offset )Whether an offset existspublicmixedoffsetGet( mixed$offset )Offset to retrievepublicvoidoffsetSet(mixed$offset,mixed$value)Offset to setpublicvoidoffsetUnset( mixed$offset )Offset to unsetpublicvoidremove( mixed$key )Removes an element from the bagpublicvoidset(mixed$key,mixed$value)Sets an element in the bagprotectedarraynormalizeItems( array$items )Normalizes the items at construction time. Identity in the base;protectedstringnormalizeKey( mixed$key )Normalizes a key for lookups and writes. Identity in the base;

Properties

protectedarray$items = []

Methods

Public · 17

__construct()

public function __construct( array $items = [] );

AbstractBag constructor.

all()

public function all(): array;

Returns all the elements of the bag

count()

public function count(): int;

Returns the number of elements in the bag

get()

public function get(
    mixed $key,
    mixed $defaultValue = null
): mixed;

Returns an element of the bag, or the default value if it is not set

getArray()

public function getArray(
    mixed $key,
    array $defaultValue = []
): array;

Returns an element of the bag as an array. The default value is returned if the element is not set or is not an array

getBool()

public function getBool(
    mixed $key,
    bool $defaultValue = false
): bool;

Returns an element of the bag cast to bool, or the default value if it is not set

getFloat()

public function getFloat(
    mixed $key,
    float $defaultValue = 0.0
): float;

Returns an element of the bag cast to float, or the default value if it is not set

getInt()

public function getInt(
    mixed $key,
    int $defaultValue = 0
): int;

Returns an element of the bag cast to int, or the default value if it is not set

getIterator()

public function getIterator(): Traversable;

Returns the iterator of the bag

getString()

public function getString(
    mixed $key,
    string $defaultValue = ""
): string;

Returns an element of the bag cast to string, or the default value if it is not set

has()

public function has( mixed $key ): bool;

Checks whether an element exists in the bag

offsetExists()

public function offsetExists( mixed $offset ): bool;

Whether an offset exists

offsetGet()

public function offsetGet( mixed $offset ): mixed;

Offset to retrieve

offsetSet()

public function offsetSet(
    mixed $offset,
    mixed $value
): void;

Offset to set

offsetUnset()

public function offsetUnset( mixed $offset ): void;

Offset to unset

remove()

public function remove( mixed $key ): void;

Removes an element from the bag

set()

public function set(
    mixed $key,
    mixed $value
): void;

Sets an element in the bag

Protected · 2

normalizeItems()

protected function normalizeItems( array $items ): array;

Normalizes the items at construction time. Identity in the base; subclasses can override it to normalize keys

normalizeKey()

protected function normalizeKey( mixed $key ): string;

Normalizes a key for lookups and writes. Identity in the base; subclasses can override it to change key handling

Http\Request\Bag\AttributeBag

ClassSource on GitHub

Holds the request attributes: arbitrary, application-defined values attached to the request during its lifecycle (router, dispatcher, security components etc.). Unlike the other request bags, it is not hydrated from a superglobal - it always starts empty.

The base class supplies the entire surface; this class exists as a distinct type so DI typing and IDE autocomplete stay precise.

Http\Request\Exception

ClassSource on GitHub

Phalcon\Http\Request\Exception

Exceptions thrown in Phalcon\Http\Request will use this class

Http\Request\Exceptions\FilterServiceUnavailable

ClassSource on GitHub

Uses Phalcon\Http\Request\Exception

Method Summary

Methods

Public · 1

__construct()

public function __construct();

Http\Request\Exceptions\InvalidHost

ClassSource on GitHub
  • \UnexpectedValueException
    • Phalcon\Http\Request\Exceptions\InvalidHost

Uses UnexpectedValueException

Method Summary

Methods

Public · 1

__construct()

public function __construct( string $host );

Http\Request\Exceptions\InvalidHttpMethod

ClassSource on GitHub

Uses Phalcon\Http\Request\Exception

Method Summary

Methods

Public · 1

__construct()

public function __construct( string $method );

Http\Request\Exceptions\MissingFilters

ClassSource on GitHub

Uses Phalcon\Http\Request\Exception

Method Summary

Methods

Public · 1

__construct()

public function __construct( string $name );

Http\Request\Exceptions\NullKeyException

ClassSource on GitHub

Thrown by AbstractBag::offsetSet() when a null offset is used (the ArrayAccess append form). Bags are always string-keyed, so an auto-indexed write could never be addressed by the caller.

Uses Phalcon\Http\Request\Exception

Method Summary

Methods

Public · 1

__construct()

public function __construct();

Http\Request\Exceptions\SanitizerNotFound

ClassSource on GitHub

Uses Phalcon\Http\Request\Exception

Method Summary

Methods

Public · 1

__construct()

public function __construct( string $sanitizer );

Http\Request\File

ClassSource on GitHub

Phalcon\Http\Request\File

Provides OO wrappers to the $_FILES superglobal

use Phalcon\Mvc\Controller;

class PostsController extends Controller
{
    public function uploadAction()
    {
        // Check if the user has uploaded files
        if ($this->request->hasFiles() == true) {
            // Print the real file names and their sizes
            foreach ($this->request->getUploadedFiles() as $file) {
                echo $file->getName(), " ", $file->getSize(), "\n";
            }
        }
    }
}

Uses Phalcon\Contracts\Http\HttpTypes · Phalcon\Traits\Support\Helper\Arr\GetTrait

Method Summary

Properties

protectedint$error = 0
protectedstring$extension = ""
protectedstring$key = ""
protectedstring$name = ""
protectedstring$realType
protectedint$size = 0
protectedstring$tmpName = ""
protectedstring$type = ""

Methods

Public · 11

__construct()

public function __construct(
    array $file,
    string $key = ""
);

Constructor

getError()

public function getError(): int;

getExtension()

public function getExtension(): string;

getKey()

public function getKey(): string;

getName()

public function getName(): string;

Returns the real name of the uploaded file

getRealType()

public function getRealType(): string;

Gets the real mime type of the upload file using finfo

getSize()

public function getSize(): int;

Returns the file size of the uploaded file

getTempName()

public function getTempName(): string;

Returns the temporary name of the uploaded file

getType()

public function getType(): string;

Returns the mime type reported by the browser This mime type is not completely secure, use getRealType() instead

isUploadedFile()

public function isUploadedFile(): bool;

Checks whether the file has been uploaded via Post.

moveTo()

public function moveTo( string $destination ): bool;

Moves the temporary file to a destination within the application

Http\Request\FileInterface

InterfaceSource on GitHub

Interface for Phalcon\Http\Request\File

  • Phalcon\Http\Request\FileInterface

Method Summary

Methods

Public · 7

getError()

public function getError(): int;

Returns the error if any

getName()

public function getName(): string;

Returns the real name of the uploaded file

getRealType()

public function getRealType(): string;

Gets the real mime type of the upload file using finfo

getSize()

public function getSize(): int;

Returns the file size of the uploaded file

getTempName()

public function getTempName(): string;

Returns the temporal name of the uploaded file

getType()

public function getType(): string;

Returns the mime type reported by the browser This mime type is not completely secure, use getRealType() instead

moveTo()

public function moveTo( string $destination ): bool;

Move the temporary file to a destination

Http\Response

ClassSource on GitHub

Part of the HTTP cycle is return responses to the clients. Phalcon\HTTP\Response is the Phalcon component responsible to achieve this task. HTTP responses are usually composed by headers and body.

$response = new \Phalcon\Http\Response();

$response->setStatusCode(200, "OK");
$response->setContent("<html><body>Hello</body></html>");

$response->send();

Uses DateTime · DateTimeZone · Phalcon\Di\Di · Phalcon\Di\DiInterface · Phalcon\Di\InjectionAwareInterface · Phalcon\Events\EventsAwareInterface · Phalcon\Events\ManagerInterface · Phalcon\Events\Traits\EventsAwareTrait · Phalcon\Http\Message\ResponseStatusCodeInterface · Phalcon\Http\Response\CookiesInterface · Phalcon\Http\Response\Exception · Phalcon\Http\Response\Exceptions\NonStandardStatusCodeRequiresMessage · Phalcon\Http\Response\Exceptions\ResponseAlreadySent · Phalcon\Http\Response\Exceptions\UrlServiceUnavailable · Phalcon\Http\Response\Headers · Phalcon\Http\Response\HeadersInterface · Phalcon\Http\Traits\StatusPhrasesTrait · Phalcon\Mvc\Url\UrlInterface · Phalcon\Mvc\ViewInterface · Phalcon\Support\Helper\File\Basename · Phalcon\Support\Helper\Json\Encode · Phalcon\Traits\Php\InfoTrait · Phalcon\Traits\Php\UrlTrait

Method Summary

public__construct(string|null$content = null,mixed$code = null,mixed$status = null)ConstructorpublicResponseInterfaceappendContent( mixed$content )Appends a string to the HTTP response bodypublicstringgetContent()Gets the HTTP response bodypublicCookiesInterfacegetCookies()Returns cookies set by the userpublicDiInterfacegetDI()Returns the internal dependency injectorpublicHeadersInterfacegetHeaders()Returns headers set by the userpublicstring|nullgetReasonPhrase()Returns the reason phrasepublicint|nullgetStatusCode()Returns the status codepublicboolhasHeader( string$name )Checks if a header existspublicboolisSent()Check if the response is already sentpublicResponseInterfaceredirect(mixed$location = null,bool$externalRedirect = false,int$statusCode = 302)Redirect by HTTP to another action or URLpublicResponseInterfaceremoveHeader( string$name )Remove a header in the responsepublicResponseInterfaceresetHeaders()Resets all the established headerspublicResponseInterfacesend()Prints out HTTP response to the clientpublicResponseInterfacesendCookies()Sends cookies to the clientpublicResponseInterface|boolsendHeaders()Sends headers to the clientpublicResponseInterfacesetCache( int$minutes )Sets Cache headers to use HTTP cachepublicResponseInterfacesetContent( string$content )Sets HTTP response bodypublicResponseInterfacesetContentLength( int$contentLength )Sets the response content-lengthpublicResponseInterfacesetContentType(string$contentType,string|null$charset = null)Sets the response content-type mime, optionally the charsetpublicResponseInterfacesetCookies( CookiesInterface$cookies )Sets a cookies bag for the response externallypublicvoidsetDI( DiInterface$container )Sets the dependency injectorpublicResponseInterfacesetEtag( string$etag )Set a custom ETagpublicResponseInterfacesetExpires( DateTime$datetime )Sets an Expires header in the response that allows to use the HTTP cachepublicResponseInterfacesetFileToSend(string$filePath,mixed$attachmentName = null,bool$attachment = true)Sets an attached file to be sent at the end of the requestpublicResponseInterfacesetHeader(string$name,mixed$value)Overwrites a header in the responsepublicResponseInterfacesetHeaders( HeadersInterface$headers )Sets a headers bag for the response externallypublicResponseInterfacesetJsonContent(mixed$content,int$jsonOptions = 0,int$depth = 512)Sets HTTP response body. The parameter is automatically converted to JSONpublicResponseInterfacesetLastModified( DateTime$datetime )Sets Last-Modified headerpublicResponseInterfacesetNotModified()Sends a Not-Modified responsepublicResponseInterfacesetRawHeader( string$header )Send a raw header to the responsepublicResponseInterfacesetStatusCode(int$code,string|null$message = null)Sets the HTTP response code

Properties

protectedDiInterface|null$container = null
protectedstring|null$content = null
protectedCookiesInterface|null$cookies = null
protectedEncode$encode
protectedstring|null$file = null
protectedHeaders$headers
protectedbool$sent = false

Methods

Public · 32

__construct()

public function __construct(
    string|null $content = null,
    mixed $code = null,
    mixed $status = null
);

Constructor

appendContent()

public function appendContent( mixed $content ): ResponseInterface;

Appends a string to the HTTP response body

getContent()

public function getContent(): string;

Gets the HTTP response body

getCookies()

public function getCookies(): CookiesInterface;

Returns cookies set by the user

getDI()

public function getDI(): DiInterface;

Returns the internal dependency injector

getHeaders()

public function getHeaders(): HeadersInterface;

Returns headers set by the user

getReasonPhrase()

public function getReasonPhrase(): string|null;

Returns the reason phrase

echo $response->getReasonPhrase();

getStatusCode()

public function getStatusCode(): int|null;

Returns the status code

echo $response->getStatusCode();

hasHeader()

public function hasHeader( string $name ): bool;

Checks if a header exists

$response->hasHeader("Content-Type");

isSent()

public function isSent(): bool;

Check if the response is already sent

redirect()

public function redirect(
    mixed $location = null,
    bool $externalRedirect = false,
    int $statusCode = 302
): ResponseInterface;

Redirect by HTTP to another action or URL

// Using a string redirect (internal/external)
$response->redirect("posts/index");
$response->redirect("https://en.wikipedia.org", true);
$response->redirect("http://www.example.com/new-location", true, 301);

// Making a redirection based on a named route
$response->redirect(
    [
        "for"        => "index-lang",
        "lang"       => "jp",
        "controller" => "index",
    ]
);

removeHeader()

public function removeHeader( string $name ): ResponseInterface;

Remove a header in the response

$response->removeHeader("Expires");

resetHeaders()

public function resetHeaders(): ResponseInterface;

Resets all the established headers

send()

public function send(): ResponseInterface;

Prints out HTTP response to the client

sendCookies()

public function sendCookies(): ResponseInterface;

Sends cookies to the client

sendHeaders()

public function sendHeaders(): ResponseInterface|bool;

Sends headers to the client

setCache()

public function setCache( int $minutes ): ResponseInterface;

Sets Cache headers to use HTTP cache

$this->response->setCache(60);

setContent()

public function setContent( string $content ): ResponseInterface;

Sets HTTP response body

$response->setContent("<h1>Hello!</h1>");

setContentLength()

public function setContentLength( int $contentLength ): ResponseInterface;

Sets the response content-length

$response->setContentLength(2048);

setContentType()

public function setContentType(
    string $contentType,
    string|null $charset = null
): ResponseInterface;

Sets the response content-type mime, optionally the charset

$response->setContentType("application/pdf");
$response->setContentType("text/plain", "UTF-8");

setCookies()

public function setCookies( CookiesInterface $cookies ): ResponseInterface;

Sets a cookies bag for the response externally

setDI()

public function setDI( DiInterface $container ): void;

Sets the dependency injector

setEtag()

public function setEtag( string $etag ): ResponseInterface;

Set a custom ETag

$response->setEtag(
    md5(
        time()
    )
);

setExpires()

public function setExpires( DateTime $datetime ): ResponseInterface;

Sets an Expires header in the response that allows to use the HTTP cache

$this->response->setExpires(
    new DateTime()
);

setFileToSend()

public function setFileToSend(
    string $filePath,
    mixed $attachmentName = null,
    bool $attachment = true
): ResponseInterface;

Sets an attached file to be sent at the end of the request

setHeader()

public function setHeader(
    string $name,
    mixed $value
): ResponseInterface;

Overwrites a header in the response

$response->setHeader("Content-Type", "text/plain");

setHeaders()

public function setHeaders( HeadersInterface $headers ): ResponseInterface;

Sets a headers bag for the response externally

setJsonContent()

public function setJsonContent(
    mixed $content,
    int $jsonOptions = 0,
    int $depth = 512
): ResponseInterface;

Sets HTTP response body. The parameter is automatically converted to JSON and also sets default header: Content-Type: “application/json; charset=UTF-8”

$response->setJsonContent(
    [
        "status" => "OK",
    ]
);

setLastModified()

public function setLastModified( DateTime $datetime ): ResponseInterface;

Sets Last-Modified header

$this->response->setLastModified(
    new DateTime()
);

setNotModified()

public function setNotModified(): ResponseInterface;

Sends a Not-Modified response

setRawHeader()

public function setRawHeader( string $header ): ResponseInterface;

Send a raw header to the response

$response->setRawHeader("HTTP/1.1 404 Not Found");

setStatusCode()

public function setStatusCode(
    int $code,
    string|null $message = null
): ResponseInterface;

Sets the HTTP response code

$response->setStatusCode(404, "Not Found");

Http\ResponseInterface

InterfaceSource on GitHub

Phalcon\Http\Response

Interface for Phalcon\Http\Response

  • Phalcon\Http\ResponseInterface

Uses DateTime · Phalcon\Http\Response\HeadersInterface

Method Summary

publicResponseInterfaceappendContent( string$content )Appends a string to the HTTP response bodypublicstringgetContent()Gets the HTTP response bodypublicHeadersInterfacegetHeaders()Returns headers set by the userpublicint|nullgetStatusCode()Returns the status codepublicboolhasHeader( string$name )Checks if a header existspublicboolisSent()Checks if the response was already sentpublicResponseInterfaceredirect(string|null$location = null,bool$externalRedirect = false,int$statusCode = 302)Redirect by HTTP to another action or URLpublicResponseInterfaceresetHeaders()Resets all the established headerspublicResponseInterfacesend()Prints out HTTP response to the clientpublicResponseInterfacesendCookies()Sends cookies to the clientpublicbool|ResponseInterfacesendHeaders()Sends headers to the clientpublicResponseInterfacesetContent( string$content )Sets HTTP response bodypublicResponseInterfacesetContentLength( int$contentLength )Sets the response content-lengthpublicResponseInterfacesetContentType(string$contentType,string|null$charset = null)Sets the response content-type mime, optionally the charsetpublicResponseInterfacesetExpires( DateTime$datetime )Sets output expire time headerpublicResponseInterfacesetFileToSend(string$filePath,string|null$attachmentName = null)Sets an attached file to be sent at the end of the requestpublicResponseInterfacesetHeader(string$name,string$value)Overwrites a header in the responsepublicResponseInterfacesetJsonContent( mixed$content )Sets HTTP response body. The parameter is automatically converted to JSONpublicResponseInterfacesetNotModified()Sends a Not-Modified responsepublicResponseInterfacesetRawHeader( string$header )Send a raw header to the responsepublicResponseInterfacesetStatusCode(int$code,string|null$message = null)Sets the HTTP response code

Methods

Public · 21

appendContent()

public function appendContent( string $content ): ResponseInterface;

Appends a string to the HTTP response body

getContent()

public function getContent(): string;

Gets the HTTP response body

getHeaders()

public function getHeaders(): HeadersInterface;

Returns headers set by the user

getStatusCode()

public function getStatusCode(): int|null;

Returns the status code

hasHeader()

public function hasHeader( string $name ): bool;

Checks if a header exists

isSent()

public function isSent(): bool;

Checks if the response was already sent

redirect()

public function redirect(
    string|null $location = null,
    bool $externalRedirect = false,
    int $statusCode = 302
): ResponseInterface;

Redirect by HTTP to another action or URL

resetHeaders()

public function resetHeaders(): ResponseInterface;

Resets all the established headers

send()

public function send(): ResponseInterface;

Prints out HTTP response to the client

sendCookies()

public function sendCookies(): ResponseInterface;

Sends cookies to the client

sendHeaders()

public function sendHeaders(): bool|ResponseInterface;

Sends headers to the client

setContent()

public function setContent( string $content ): ResponseInterface;

Sets HTTP response body

setContentLength()

public function setContentLength( int $contentLength ): ResponseInterface;

Sets the response content-length

setContentType()

public function setContentType(
    string $contentType,
    string|null $charset = null
): ResponseInterface;

Sets the response content-type mime, optionally the charset

@todo check the null

setExpires()

public function setExpires( DateTime $datetime ): ResponseInterface;

Sets output expire time header

setFileToSend()

public function setFileToSend(
    string $filePath,
    string|null $attachmentName = null
): ResponseInterface;

Sets an attached file to be sent at the end of the request

@todo check the null

setHeader()

public function setHeader(
    string $name,
    string $value
): ResponseInterface;

Overwrites a header in the response

setJsonContent()

public function setJsonContent( mixed $content ): ResponseInterface;

Sets HTTP response body. The parameter is automatically converted to JSON

$response->setJsonContent(
    [
        "status" => "OK",
    ]
);

@todo check the parameter type

setNotModified()

public function setNotModified(): ResponseInterface;

Sends a Not-Modified response

setRawHeader()

public function setRawHeader( string $header ): ResponseInterface;

Send a raw header to the response

setStatusCode()

public function setStatusCode(
    int $code,
    string|null $message = null
): ResponseInterface;

Sets the HTTP response code

@todo change $message to only string

Http\Response\Cookies

ClassSource on GitHub

This class is a bag to manage the cookies.

A cookies bag is automatically registered as part of the ‘response’ service in the DI. By default, cookies are automatically encrypted before being sent to the client and are decrypted when retrieved from the user. To set sign key used to generate a message authentication code use Phalcon\Http\Response\Cookies::setSignKey().

use Phalcon\Di\Di;
use Phalcon\Encryption\Crypt;
use Phalcon\Http\Response\Cookies;

$di = new Di();

$di->set(
    'crypt',
    function () {
        $crypt = new Crypt();

        // The `$key' should have been previously generated in a
        // cryptographically safe way.
        $key =
        "T4\xb1\x8d\xa9\x98\x05\\\x8c\xbe\x1d\x07&[\x99\x18\xa4~Lc1\xbeW\xb3";

        $crypt->setKey($key);

        return $crypt;
    }
);

$di->set(
    'cookies',
    function () {
        $cookies = new Cookies();

        // The `$key' MUST be at least 32 characters long and generated
        // using a cryptographically secure pseudo random generator.
        $key =
        "#1dj8$=dp?.ak//j1V$~%*0XaK\xb1\x8d\xa9\x98\x054t7w!z%C*F-Jk\x98\x05\\\x5c";

        $cookies->setSignKey($key);

        return $cookies;
    }
);

Uses Phalcon\Contracts\Http\HttpTypes · Phalcon\Di\AbstractInjectionAware · Phalcon\Di\DiInterface · Phalcon\Http\Cookie · Phalcon\Http\Cookie\CookieInterface · Phalcon\Http\Cookie\Exception · Phalcon\Http\Response\Exceptions\ResponseServiceUnavailable · Phalcon\Http\Traits\EncryptionAwareTrait

Method Summary

Properties

protectedarray$cookies = []
protectedbool$isRegistered = false
protectedbool$isSent = false
protectedstring|null$signKey = nullThe cookie's sign key.

Methods

Public · 11

__construct()

public function __construct(
    bool $useEncryption = true,
    string|null $signKey = null
);

Constructor

delete()

public function delete( string $name ): bool;

Deletes a cookie by its name This method does not remove cookies from the _COOKIE super-global

get()

public function get( string $name ): CookieInterface;

Gets a cookie from the bag

getCookies()

public function getCookies(): array;

Gets all cookies from the bag

has()

public function has( string $name ): bool;

Check if a cookie is defined in the bag or exists in the _COOKIE super-global

isSent()

public function isSent(): bool;

Returns if the headers have already been sent

reset()

public function reset(): CookiesInterface;

Reset set cookies

send()

public function send(): bool;

Sends the cookies to the client Cookies aren’t sent if headers are sent in the current request

set()

public function set(
    string $name,
    mixed $value = null,
    int $expire = 0,
    string $path = "/",
    bool $secure = false,
    string $domain = "",
    bool $httpOnly = false,
    array $options = []
): CookiesInterface;

Sets a cookie to be sent at the end of the request.

This method overrides any cookie set before with the same name.

use Phalcon\Http\Response\Cookies;

$now = new DateTimeImmutable();
$tomorrow = $now->modify('tomorrow');

$cookies = new Cookies();
$cookies->set(
    'remember-me',
    json_encode(['user_id' => 1]),
    (int) $tomorrow->format('U'),
);

setSignKey()

public function setSignKey( string|null $signKey = null ): CookiesInterface;

Sets the cookie’s sign key.

The `$signKey’ MUST be at least 32 characters long and generated using a cryptographically secure pseudo random generator.

Use NULL to disable cookie signing.

@see \Phalcon\Encryption\Security\Random

useEncryption()

public function useEncryption( bool $useEncryption ): CookiesInterface;

Set if cookies in the bag must be automatically encrypted/decrypted

Http\Response\CookiesInterface

InterfaceSource on GitHub

Interface for Phalcon\Http\Response\Cookies

  • Phalcon\Http\Response\CookiesInterface

Uses Phalcon\Contracts\Http\HttpTypes · Phalcon\Http\Cookie\CookieInterface

Method Summary

Methods

Public · 8

delete()

public function delete( string $name ): bool;

Deletes a cookie by its name This method does not removes cookies from the _COOKIE superglobal

get()

public function get( string $name ): CookieInterface;

Gets a cookie from the bag

has()

public function has( string $name ): bool;

Check if a cookie is defined in the bag or exists in the _COOKIE superglobal

isUsingEncryption()

public function isUsingEncryption(): bool;

Returns if the bag is automatically encrypting/decrypting cookies

reset()

public function reset(): CookiesInterface;

Reset set cookies

send()

public function send(): bool;

Sends the cookies to the client

set()

public function set(
    string $name,
    mixed $value = null,
    int $expire = 0,
    string $path = "/",
    bool $secure = false,
    string $domain = "",
    bool $httpOnly = false,
    array $options = []
): CookiesInterface;

Sets a cookie to be sent at the end of the request

useEncryption()

public function useEncryption( bool $useEncryption ): CookiesInterface;

Set if cookies in the bag must be automatically encrypted/decrypted

Http\Response\Exception

ClassSource on GitHub

Phalcon\Http\Response\Exception

Exceptions thrown in Phalcon\Http\Response will use this class.

Http\Response\Exceptions\NonStandardStatusCodeRequiresMessage

ClassSource on GitHub

Uses Phalcon\Http\Response\Exception

Method Summary

Methods

Public · 1

__construct()

public function __construct();

Http\Response\Exceptions\ResponseAlreadySent

ClassSource on GitHub

Uses Phalcon\Http\Response\Exception

Method Summary

Methods

Public · 1

__construct()

public function __construct();

Http\Response\Exceptions\ResponseServiceUnavailable

ClassSource on GitHub

Uses Phalcon\Http\Response\Exception

Method Summary

Methods

Public · 1

__construct()

public function __construct();

Http\Response\Exceptions\UrlServiceUnavailable

ClassSource on GitHub

Uses Phalcon\Http\Response\Exception

Method Summary

Methods

Public · 1

__construct()

public function __construct();

Http\Response\Headers

ClassSource on GitHub

This class is a bag to manage the response headers

@implements IteratorAggregate<string, string|null>

Uses IteratorAggregate · Phalcon\Contracts\Http\HttpTypes · Traversable

Method Summary

Properties

protectedarray$headers = []
protectedbool$isSent = false

Methods

Public · 10

get()

public function get( string $name ): string|bool|null;

Gets a header value from the internal bag

getIterator()

public function getIterator(): Traversable;

has()

public function has( string $name ): bool;

Checks if a header exists

isSent()

public function isSent(): bool;

Returns if the headers have already been sent

remove()

public function remove( string $header ): HeadersInterface;

Removes a header by its name

reset()

public function reset(): void;

Reset set headers

send()

public function send(): bool;

Sends the headers to the client

set()

public function set(
    string $name,
    string $value
): HeadersInterface;

Sets a header to be sent at the end of the request

setRaw()

public function setRaw( string $header ): HeadersInterface;

Sets a raw header to be sent at the end of the request

toArray()

public function toArray(): array;

Returns the current headers as an array

Http\Response\HeadersInterface

InterfaceSource on GitHub

Interface for Phalcon\Http\Response\Headers compatible bags

  • Phalcon\Http\Response\HeadersInterface

Method Summary

Methods

Public · 6

get()

public function get( string $name ): bool|string|null;

Gets a header value from the internal bag

has()

public function has( string $name ): bool;

Checks if a header exists

reset()

public function reset(): void;

Reset set headers

send()

public function send(): bool;

Sends the headers to the client

set()

public function set(
    string $name,
    string $value
): HeadersInterface;

Sets a header to be sent at the end of the request

setRaw()

public function setRaw( string $header ): HeadersInterface;

Sets a raw header to be sent at the end of the request

Http\Traits\EncryptionAwareTrait

TraitSource on GitHub

Provides the implicit encryption flag and its accessor shared by the HTTP cookie classes.

  • Phalcon\Http\Traits\EncryptionAwareTrait

Used by Phalcon\Http\Cookie · Phalcon\Http\Response\Cookies

Method Summary

Properties

protectedbool$useEncryption = false

Methods

Public · 1

isUsingEncryption()

public function isUsingEncryption(): bool;

Check if implicit encryption is being used

Http\Traits\StatusPhrasesTrait

TraitSource on GitHub

Status Phrases trait

  • Phalcon\Http\Traits\StatusPhrasesTrait

Uses Phalcon\Http\Message\ResponseStatusCodeInterface

Used by Phalcon\Http\Response

Method Summary

Methods

Protected · 1

getPhrases()

protected function getPhrases(): array;

Returns the list of status codes available

Type to search…

↑↓ navigate↵ selectEsc close