Bug #60541 [Bgs]: FILTER_SANITIZE_NUMBER_INT fails to filter strings with plus and minus
| From: | cataphract@php.net | Date: | Sat, 17 Dec 2011 14:31:51 +0000 |
| Subject: | Bug #60541 [Bgs]: FILTER_SANITIZE_NUMBER_INT fails to filter strings with plus and minus | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-165936@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=60541&edit=1
ID: 60541
Updated by: cataphract@php.net
Reported by: klaussilveira@php.net
Summary: FILTER_SANITIZE_NUMBER_INT fails to filter strings
with plus and minus
Status: Bogus
Type: Bug
Package: Filter related
Operating System: UNIX
PHP Version: 5.3.8
Block user comment: N
Private report: N
New Comment:
Plus, this matches perfectly the documentation ("Remove all characters except digits, plus and
minus sign.")
Previous Comments:
------------------------------------------------------------------------
[2011-12-17 14:31:16] cataphract@php.net
The purpose of the sanitisation filters is not to transform data so as to make it valid, it merely
"removes undesirable characters" (see http://php.net/manual/en/intro.filter.php ).
Though this description is not entirely correct (for instance FILTER_SANITIZE_SPECIAL_CHARS with
FILTER_FLAG_ENCODE_HIGH will transform some characters into HTML entities -- in a rather flawed way,
I must say, because it arbitrarily assumes a sort of ISO-8859-1 extension), what is clear is that
data may very well still be invalid after running the sanitisation filters.
------------------------------------------------------------------------
[2011-12-16 00:17:30] klaussilveira@php.net
The most elegant solution was to detect only + and - signs that are next to a
number, and remove all others. For example:
filter_var("ad--td#$@++qsdh-3", FILTER_SANITIZE_NUMBER_INT); // returns -3
Right now, the filter behavior is:
filter_var("ad--td#$@++qsdh-3", FILTER_SANITIZE_NUMBER_INT); // returns --++-3
Which is VERY bad and HORRIBLY wrong.
------------------------------------------------------------------------
[2011-12-16 00:07:42] klaussilveira@php.net
The following patch has been added/updated:
Patch Name: sanitize_integers
Revision: 1323994062
URL: https://bugs.php.net/patch-display.php?bug=60541&patch=sanitize_integers&revision=1323994062
------------------------------------------------------------------------
[2011-12-16 00:07:20] klaussilveira@php.net
Description:
------------
The filter_var FILTER_SANITIZE_NUMBER_INT filter fails to sanitize plus and minus
signs in a string. This is the expected behavior, since + and - are accepted in
an integer. However, the filter fails to recognize multiple + and -, returning an
string instead of an integer.
For example:
filter_var("I'm+captain4", FILTER_SANITIZE_NUMBER_INT; // returns +4, OK!
filter_var("I'm++captain4", FILTER_SANITIZE_NUMBER_INT; // returns ++4, FAILURE!
I wrote a small patch that makes the filter ignore + and - signs, which, i
believe, it's the best behavior for this.
Test script:
---------------
<?php
// Normal behavior
$a = filter_var("I'm+captainSp4rrow!", FILTER_SANITIZE_NUMBER_INT);
$b = filter_var("I'm+captain4", FILTER_SANITIZE_NUMBER_INT);
echo "$a and $b" . PHP_EOL;
echo $a + $b . PHP_EOL;
// Problems comes in when we have multiple minus or plus signs in the string
$a = filter_var("I'm++captainSp4rrow!", FILTER_SANITIZE_NUMBER_INT);
$b = filter_var("I'm++captain4", FILTER_SANITIZE_NUMBER_INT);
echo "$a and $b" . PHP_EOL;
echo $a + $b . PHP_EOL;
Expected result:
----------------
4 and 4
8
4 and 4
8
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=60541&edit=1