Bug #16337 Updated: include() does not decode % correctly
| From: | eru@php.net | Date: | Wed, 10 Jul 2002 00:59:06 +0000 |
| Subject: | Bug #16337 Updated: include() does not decode % correctly | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-13673@lists.php.net to get a copy of this message | ||
ID: 16337
Updated by: eru@php.net
Reported By: tmorgan-spam@kavi.com
Status: Feedback
Bug Type: HTTP related
Operating System: Unix based
PHP Version: 4.1.0
New Comment:
Judging from the RFC, I'd say you're not using the appropriate encoding
scheme. The RFC says:
base64-user-pass = <base64 encoding of user-pass>
user-pass = userid ":" password
userid = *<TEXT excluding ":">
password = *TEXT
So in your case this would be
$user_pass64 = base64_encode( $username.":".$password );
include("http://".$user_pass64."@www.example.com/");
Previous Comments:
------------------------------------------------------------------------
[2002-07-09 20:34:34] tmorgan-spam@kavi.com
You know, I would really like this bug fixed, but I am really
frustrated by the attitude I am getting here. Three and a half months
have passed, and yet not a single developer at PHP has taken 10 minutes
to attempt to replicate it themselves. I know there are a lot of bugs
in PHP that need fixing, but cmon, at least an assessment of when it is
going to be fixed. And if it IS fixed in the new release, then why
don't you tell me that?
As for example code, well, I have already given the one line that is
necessary, but I will try to make it plainer:
// GIVEN: user provided $username & $password
// What SHOULD work:
$clean_username = urlencode($username);
$clean_password = urlencode($password);
include("http://$clean_username:$clean_password@www.example.com/");
The url parser in include() needs to parse, then decode, those two
strings before passing them to the HTTP session. If you want to know
why this should be this way, read my previous comments.
------------------------------------------------------------------------
[2002-07-09 19:51:46] sniper@php.net
First, try this snapshot:
http://snaps.php.net/php4-latest.tar.gz
And if this doesn't work like you think it should work,
provide a short but complete script which clearly (!) demonstrates the
possible bug.
------------------------------------------------------------------------
[2002-05-14 01:42:13] tmorgan-spam@kavi.com
We are still having issues with this. If you require any additional
explanation, or examples, I can give them. Some indication of whether
this is being worked on or not would be nice...
------------------------------------------------------------------------
[2002-05-14 00:46:32] mfischer@php.net
Feedback was given, but status not changed. Reopening.
------------------------------------------------------------------------
[2002-05-14 00:00:04] php-bugs@lists.php.net
No feedback was provided for this bug for over a month, so it is
being suspended automatically. If you are able to provide the
information that was originally requested, please do so and change
the status of the bug back to "Open".
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
http://bugs.php.net/16337
--
Edit this bug report at http://bugs.php.net/?id=16337&edit=1