# PHP Script Redirection Issue Due to InfinityFree Security System

**URL:** https://forum.infinityfree.com/t/php-script-redirection-issue-due-to-infinityfree-security-system/92577
**Category:** Hosting Support
**Created:** [April 20, 2024, 8:08pm UTC](https://forum.infinityfree.com/t/php-script-redirection-issue-due-to-infinityfree-security-system/92577 "2024-04-20T20:08:01Z")
**Posts on this page:** 13
**Page:** 1

<div class="post-metadata">

### Author: ![beemybold](https://forum.infinityfree.com/user_avatar/forum.infinityfree.com/beemybold/32/47698_2.png) [@beemybold](https://forum.infinityfree.com/u/beemybold)
#### Post date: [April 20, 2024, 8:08pm UTC](https://forum.infinityfree.com/t/php-script-redirection-issue-due-to-infinityfree-security-system/92577/1 "2024-04-20T20:08:02Z")

</div>

### Website URL

[https://dbiblio.rf.gd](https://dbiblio.rf.gd)

### Error Message

cart.js:123 SyntaxError: Unexpected token ‘\<’, "\<!doctype "... is not valid JSON at JSON.parse ()  
at xhr.onload (cart.js:110:39)  
cart.js:122 Failed to parse JSON:

### Other Information

I’m encountering an issue with my PHP script on my website hosted on InfinityFree. When attempting to retrieve product details from my products table of my database using a PHP script, the response is unexpectedly redirected to another URL, preventing me from obtaining the JSON format of the product details as intended.

Apparently this redirection is caused by InfinityFree’s security system, which enforces restrictions on certain types of requests and clients. But, this security measure is causing my PHP script to fail when accessed through certain clients for the purpose of interacting with your (MySQL) database.

I’m reaching out to the community to see if there are any workarounds or solutions that could allow me to retrieve the product details using my PHP script without encountering the redirection issue.

Thank you in advance for your assistance and insights.

---

<div class="post-metadata">

### Author: ![Greenreader9](https://forum.infinityfree.com/user_avatar/forum.infinityfree.com/greenreader9/32/22847_2.png) [@Greenreader9](https://forum.infinityfree.com/u/Greenreader9)
#### Post date: [April 20, 2024, 9:15pm UTC](https://forum.infinityfree.com/t/php-script-redirection-issue-due-to-infinityfree-security-system/92577/2 "2024-04-20T21:15:14Z")

</div>

Your post is pretty vague, but you see, to be describing this issue:

> [@Ensuring only web browsers can access your website](https://forum.infinityfree.com/t/ensuring-only-web-browsers-can-access-your-website/49353):
>
> InfinityFree is a website hosting service. That means that the hosting accounts we provided are intended for hosting websites. Websites contain pages that are accessed through web browsers. InfinityFree is not intended to be used for file sharing, API hosting, database hosting or background tasks/tools. To help enforce this, free hosting enforces a security system that makes sure that anyone trying to access your website is using a normal web browser. This is done by checking whether the web br…

* * *

> [@beemybold](#):
>
> the response is unexpectedly redirected to another URL

What URL? What code is managing the response? How are you creating the request?

---

<div class="post-metadata">

### Author: ![Oxy](https://forum.infinityfree.com/user_avatar/forum.infinityfree.com/oxy/32/37989_2.png) [@Oxy](https://forum.infinityfree.com/u/Oxy)
#### Post date: [April 21, 2024, 7:03am UTC](https://forum.infinityfree.com/t/php-script-redirection-issue-due-to-infinityfree-security-system/92577/3 "2024-04-21T07:03:15Z")

</div>

There are other problems like encoding/charset

 ![Screenshot 2024-04-21 085925](https://forum-cdn.infinityfree.net/original/3X/0/6/06baac27d74e11aa668fbca897d9105f382b4b5a.jpeg)

and using `shell_exec()` (All PHP Shell commands are disabled on this hosting for security)

 ![Screenshot 2024-04-21 085835](https://forum-cdn.infinityfree.net/original/3X/d/0/d077475933596473a5d793076fa047c5948748c6.jpeg)

---

<div class="post-metadata">

### Author: ![Admin](https://forum.infinityfree.com/user_avatar/forum.infinityfree.com/admin/32/36437_2.png) [@Admin](https://forum.infinityfree.com/u/Admin)
#### Post date: [April 21, 2024, 8:12am UTC](https://forum.infinityfree.com/t/php-script-redirection-issue-due-to-infinityfree-security-system/92577/4 "2024-04-21T08:12:44Z")

</div>

I had a look at your website, and I’m not sure that the errors you’re seeing are a hosting issue.

As you can see, the error message says that Javascript is unable to parse text as JSON. However, when I check the Network tab in my browser, I don’t see any requests that actually return JSON.

The `update_cart.php` endpoint just returns the text `Cart data updated successfully`, which is not valid JSON. And the `get_product_details.php` endpoint doesn’t return anything at all (which is also not valid JSON).

> [@beemybold](#):
>
> But, this security measure is causing my PHP script to fail when accessed through certain clients for the purpose of interacting with your (MySQL) database.

Which clients are that? Using this code from your website hosted with us should just work. But hosting the frontend on another domain, or even on your own computer for development, will not work.

This is a little bit restrictive, but I don’t see any reason why your shop cannot work on our hosting for your customers.

> [@Oxy](#):
>
> There are other problems like encoding/charset

Usually this is caused by not configuring a MySQL charset in your code, after having entered the database contents through phpMyAdmin.

> [@Not showing persian data correctly](https://forum.infinityfree.com/t/not-showing-persian-data-correctly/91267/2):
>
> If I understand this correctly: you entered the data through phpMyAdmin, and it shows correctly there. But you query the data from your website, and it doesn’t show it correctly there? If so: You’re looking for the right thing, but in the wrong place. Collation affects how data is indexed on disk, but seeing how it is shown differently in different places, collation is not the issue. I suspect the issue is caused by the database charset of your MySQL connection in PHP. phpMyAdmin uses utf8 …

---

<div class="post-metadata">

### Author: ![anon95807532](https://forum.infinityfree.com/letter_avatar/anon95807532/32/5_5575768a8748004e209b776fc1b2916d.png) [@anon95807532](https://forum.infinityfree.com/u/anon95807532)
#### Post date: [April 21, 2024, 8:29am UTC](https://forum.infinityfree.com/t/php-script-redirection-issue-due-to-infinityfree-security-system/92577/5 "2024-04-21T08:29:31Z")

</div>

Hi beemybold,

Your website is attempting to fetch a JSON response from the host, but since your website is WordPress, if it cannot process a response due to errors like disabled functions, it will return HTML instead. When this HTML response is decoded as JSON, the characters aren’t as expected and you get decode/parsing errors.

Check your website code to see if there are such functions besides this one

> [@Oxy](#):
>
> and using `shell_exec()` (All PHP Shell commands are disabled on this hosting for security)

Cheers!

---

<div class="post-metadata">

### Author: ![beemybold](https://forum.infinityfree.com/user_avatar/forum.infinityfree.com/beemybold/32/47698_2.png) [@beemybold](https://forum.infinityfree.com/u/beemybold)
#### Post date: [April 21, 2024, 7:04pm UTC](https://forum.infinityfree.com/t/php-script-redirection-issue-due-to-infinityfree-security-system/92577/6 "2024-04-21T19:04:52Z")

</div>

> [@Greenreader9](#):
>
> What URL? What code is managing the response? How are you creating the request?

When making a request to the `get_product_details.php` script on my website hosted on InfinityFree, the response contains a JavaScript script (which I provided earlier) that redirects the browser to the following URL:([https://dbiblio.rf.gd/get\_product\_details.php?productId=BCk2hm-1711682545&i=1](https://dbiblio.rf.gd/get_product_details.php?productId=BCk2hm-1711682545&i=1))].

Here’s a simplified version of the PHP script I’m using to handle the request:

phpCopy code

```auto
<?php

// include database connection

if (isset($_GET['productId']) || isset($_GET['product_id'])) {
    $productId = isset($_GET['productId']) ? mysqli_real_escape_string($conn, $_GET['productId']) : mysqli_real_escape_string($conn, $_GET['product_id']);

    // query to fetch the product data
    $select_query = "SELECT * FROM `products` WHERE `product_id` = '$productId'";
    $result_query = mysqli_query($conn, $select_query);

    if ($result_query) {
        if ($row_data = mysqli_fetch_assoc($result_query)) {
            // Add additional properties to the $row_data array
            $row_data['coverImageUrl'] = 'admin_area/book_cover/' . $row_data['product_cover'];
            $row_data['product_stars'] = $row_data['product_rate']; // Assuming your rating is stored in product_rate

            // Output the response as JSON
            header('Content-Type: application/json');
            echo json_encode($row_data);
            exit();
        } else {
            // Handle case when product is not found
            header('Content-Type: application/json');
            echo json_encode(['error' => 'Product not found']);
            exit();
        }
    } else {
        // Handle error when fetching product details from database
        header('Content-Type: application/json');
        echo json_encode(['error' => 'Unable to fetch product details']);
        exit();
    }
} else {
    // Handle missing productId parameter
    header('Content-Type: application/json');
    echo json_encode(['error' => 'Product ID not provided']);
    exit();
}

```

In my local environment, this request return a response like this:  
{  
“product\_id”: “unique iD”,  
“product\_title”: “string”,  
“product\_price”: “float”,  
“coverImageUrl”: “filename.png”,  
}

As for how I’m creating the request, I’m simply accessing the `get_product_details.php` script through a web browser or using tools like cURL. The issue occurs consistently regardless of the method used to make the request.

I hope this additional information helps clarify the situation. If there are any further details needed, please let me know. Thank you for your assistance.

---

<div class="post-metadata">

### Author: ![beemybold](https://forum.infinityfree.com/user_avatar/forum.infinityfree.com/beemybold/32/47698_2.png) [@beemybold](https://forum.infinityfree.com/u/beemybold)
#### Post date: [April 21, 2024, 7:26pm UTC](https://forum.infinityfree.com/t/php-script-redirection-issue-due-to-infinityfree-security-system/92577/7 "2024-04-21T19:26:11Z")

</div>

Thank for bringing that up.

Regarding the encoding problem, it’s weird because it’s not happening in my local setup, so I’m guessing it might be something to do with the hosting setup. Any tips on how to fix that?

As for shell\_exec(), I’m scratching my head because I haven’t used that function anywhere in my checkout.php page. Could it be a hiccup on InfinityFree’s end, or am I missing something?

If you could shed some light on these issues, that’d be awesome.

---

<div class="post-metadata">

### Author: ![Meishin](https://forum.infinityfree.com/user_avatar/forum.infinityfree.com/meishin/32/59902_2.png) [@Meishin](https://forum.infinityfree.com/u/Meishin)
#### Post date: [April 22, 2024, 10:15am UTC](https://forum.infinityfree.com/t/php-script-redirection-issue-due-to-infinityfree-security-system/92577/8 "2024-04-22T10:15:45Z")

</div>

> [@beemybold](#):
>
> I’m simply accessing the `get_product_details.php` script through a web browser or using tools like cURL.

Read again

> [@Ensuring only web browsers can access your website](https://forum.infinityfree.com/t/ensuring-only-web-browsers-can-access-your-website/49353):
>
> InfinityFree is a website hosting service. That means that the hosting accounts we provided are intended for hosting websites. Websites contain pages that are accessed through web browsers. InfinityFree is not intended to be used for file sharing, API hosting, database hosting or background tasks/tools. To help enforce this, free hosting enforces a security system that makes sure that anyone trying to access your website is using a normal web browser. This is done by checking whether the web br…

In short, even if you think you are “simply accessing your website with cURL”, it won’t work. This is the intended behaviour.

Those requests can only work with Javascript AJAX in the same website, not somewhere outside of your website.

---

<div class="post-metadata">

### Author: ![Admin](https://forum.infinityfree.com/user_avatar/forum.infinityfree.com/admin/32/36437_2.png) [@Admin](https://forum.infinityfree.com/u/Admin)
#### Post date: [April 22, 2024, 6:05pm UTC](https://forum.infinityfree.com/t/php-script-redirection-issue-due-to-infinityfree-security-system/92577/9 "2024-04-22T18:05:26Z")

</div>

> [@beemybold](#):
>
> Could it be a hiccup on InfinityFree’s end, or am I missing something?

A server “hiccup” can’t make code appear out of nowhere.

> [@beemybold](#):
>
> Here’s a simplified version of the PHP script I’m using to handle the request:

All of the code returns hard coded values, except for one:

```auto
            // Output the response as JSON
            header('Content-Type: application/json');
            echo json_encode($row_data);
            exit();

```

Given that the page returns empty, apparently the `echo json_encode(...)` line returns empty.

If we look at the documentation of `json_encode`, we see that it will return `false` if the data cannot be converted to JSON, and if you do `echo false;`, you will see nothing.

We established before that you have character encoding issues with your database connection. And the PHP docs for `json_encode` say that:

> All string data must be UTF-8 encoded.

And we’ve already seen on your web page that this is not the case.

So I think that if you fix the character encoding encoding issue with your database connection, the JSON endpoints will work too.

---

<div class="post-metadata">

### Author: ![beemybold](https://forum.infinityfree.com/user_avatar/forum.infinityfree.com/beemybold/32/47698_2.png) [@beemybold](https://forum.infinityfree.com/u/beemybold)
#### Post date: [April 26, 2024, 5:01pm UTC](https://forum.infinityfree.com/t/php-script-redirection-issue-due-to-infinityfree-security-system/92577/10 "2024-04-26T17:01:36Z")

</div>

### Website URL

[https://dbiblio.rf.gd/](https://dbiblio.rf.gd/)

### Error Message

 ![Screenshot 2024-04-25 at 21.25.13](https://infinityfree-forum-uploads.s3.dualstack.eu-central-1.amazonaws.com/original/3X/0/a/0a792c15d1124699de76315c95eb8faa2e7f4ccd.jpeg)

### Other Information

I created a MySQL database on [https://cpanel.infinityfree.com/](https://cpanel.infinityfree.com/) for my website but I’m encountering encoding issues because the text with special characters are not being rendered properly. I tweaked the table’s collation between utf8mb4\_unicode\_520\_ci, utf8mb4\_unicode\_ci and utf8mb4\_general\_ci but nothing has changed. I don’t have this issues on my localhost.

How can I fix it?

---

<div class="post-metadata">

### Author: ![anon95807532](https://forum.infinityfree.com/letter_avatar/anon95807532/32/5_5575768a8748004e209b776fc1b2916d.png) [@anon95807532](https://forum.infinityfree.com/u/anon95807532)
#### Post date: [April 27, 2024, 6:51am UTC](https://forum.infinityfree.com/t/php-script-redirection-issue-due-to-infinityfree-security-system/92577/11 "2024-04-27T06:51:29Z")

</div>

Hi beemybold,

> [@beemybold](#):
>
> When making a request to the `get_product_details.php` script on my website hosted on InfinityFree, the response contains a JavaScript script (which I provided earlier) that redirects the browser to the following URL:([https://dbiblio.rf.gd/get\_product\_details.php?productId=BCk2hm-1711682545&i=1](https://dbiblio.rf.gd/get_product_details.php?productId=BCk2hm-1711682545&i=1))].

This is expected behavior due to the security system on IF, if you attempt to use non-browser tools like CURL or Postman, it won’t work. The i=1 appended query parameter shows this behavior.

To correctly test your page, you should use a browser as your page is expecting a GET request anyways. Your browser can understand the security system and will redirect to your ajax request without issues. What matters here is that your page can produce a result that works out a json response instead of an HTML.

I’ve revised your code as follows for better debugging insights and easier reading:

```php
<?php

header('content-Type: application/json; charset="utf-8"');

if(!array_key_exists('productId', $_GET)){
    echo json_encode([
        'error' => 'Product ID is missing.',
    ]);
    exit(400);
}

$product_id = trim($_GET['$product_id']);
if(empty($product_id)){
    echo json_encode([
        'error' => 'Product ID is empty.',
    ]);
    exit(400);
}

if(!!!preg_match('/^[a-zA-Z0-9\-]$/', $product_id)){
    echo json_encode([
        'error' => 'Product ID is invalid.',
    ]);
    exit(400);
}

$query = sprintf('SELECT * FROM `products` WHERE `product_id` = "%s"', mysqli_real_escape_string($conn, $product_id));
$result = mysqli_query($conn, $query);
if (!$result) {
    echo json_encode([
        'error' => 'Product ID is not found.',
    ]);
    exit(404);
}

$data = mysqli_fetch_assoc($result);
if(sizeof($data) === 0){
    echo json_encode([
        'error' => 'Product ID is not found.',
    ]);
    exit(404);
}

$data['coverImageUrl'] = 'path_to_default_image';
if(array_key_exists('product_cover', $data) && !empty($data['$product_cover'])){
    // make an attempt to check if the file exists here
    $data['coverImageUrl'] = sprintf('admin_area/book_cover/%s', $data['product_cover']);
}

$data['product_stars'] = intval($data['product_rate']);
echo json_encode($data);
exit(200);

```

Meanwhile, there’s one more encoding that will involve in your website display - your code’s encoding. Even if you set the meta charset to UTF-8, if the file itself is not then things will still go south. To change that, use Notepad++ and change the file encoding to UTF-8 (without the DOM).

Also `mysqli_real_escape_string` is no longer considered secure, and you should seek solutions like PDO, or use framework query methods.

P.S. I’ve read another post on this forum saying that websites that have been mentioned here was DDoSed, and I also find yours suspended due to hit limits, you might want to reach out to support for solution on that one to continue solving the matter here.

Cheers!

---

<div class="post-metadata">

### Author: ![Admin](https://forum.infinityfree.com/user_avatar/forum.infinityfree.com/admin/32/36437_2.png) [@Admin](https://forum.infinityfree.com/u/Admin)
#### Post date: [April 27, 2024, 8:43am UTC](https://forum.infinityfree.com/t/php-script-redirection-issue-due-to-infinityfree-security-system/92577/12 "2024-04-27T08:43:41Z")

</div>

> [@beemybold](#):
>
> How can I fix it?

You need to set the database charset on the database connection in your PHP code. phpMyAdmin uses `utf8` by default, but PHP uses `latin1`. So data created through phpMyAdmin will end up garbled on your website and vice versa. The charset and collation in your database doesn’t really matter for this.

For MySQLi: [PHP: mysqli::set\_charset - Manual](https://www.php.net/manual/en/mysqli.set-charset.php)  
For PDO: [PHP: PDO\_MYSQL DSN - Manual](https://www.php.net/manual/en/ref.pdo-mysql.connection.php)

---

<div class="post-metadata">

### Author: ![system](https://infinityfree-forum-uploads.s3.dualstack.eu-central-1.amazonaws.com/original/3X/b/0/b024fd3fa88bae093c9576e55c2c94e33f890206.svg) [@system](https://forum.infinityfree.com/u/system)
#### Post date: [May 4, 2024, 8:44am UTC](https://forum.infinityfree.com/t/php-script-redirection-issue-due-to-infinityfree-security-system/92577/13 "2024-05-04T08:44:27Z")

</div>

This topic was automatically closed 7 days after the last reply. New replies are no longer allowed.
