Edit report at https://bugs.php.net/bug.php?id=43225&edit=1
ID: 43225
Updated by: aharvey@php.net
Reported by: ed at bronto dot com
Summary: fputcsv incorrectly handles cells ending in \
followed by "
-Status: Closed
+Status: Re-Opened
Type: Bug
Package: Filesystem function related
Operating System: Centos
PHP Version: 5.2.4
-Assigned To: aharvey
+Assigned To:
Block user comment: N
Private report: N
New Comment:
Sadly, that was a classic case of fixing one thing and breaking another. Reopening, and unassigning
myself.
Previous Comments:
------------------------------------------------------------------------
[2013-01-15 07:35:00] aharvey@php.net
Fixed in 5.3.22 and 5.4.12: https://github.com/php/php-src/commit/9b5cb0e8059b1e8bec096067491ed8d75f878938
------------------------------------------------------------------------
[2013-01-15 07:05:38] aharvey@php.net
I've found the cause of this while writing tests for PR 197.
php_fputcsv(), while iterating over the fields to be output, has this fairly odd "escaped"
concept â once escape_char (which is hardcoded \ at present) is seen, escaping stops until the
next enclosure (" by default) is seen. It doesn't matter whether it's the following
character or not.
After that, escape_char is then ignored anyway, and the enclosure is used as the "escape"
character.
This came in via https://github.com/php/php-src/commit/af0adbed3963cdee1bfaf5e3a74b029d2b92c8b7
seven years ago to make the use of enclosures optional â the feature in general is good, but
this is definitely an issue in the implementation.
------------------------------------------------------------------------
[2009-10-09 19:57:18] mbest at icontact dot com
magicaltux@php.net is wrong. This bug is not about fgetcsv but about fputcsv. fputcsv should
always escape a double quote to two double quotes. But it doesn't do so if the field contains
\" This will mess up the CSV output such that it will not be importable in Excel or other such
programs.
------------------------------------------------------------------------
[2009-01-19 12:54:38] magicaltux@php.net
This bug is the same as bug #38918 and bug #38929.
* fputcsv() does escape values (replacing " with "", for example)
* It seems that fgetcsv() accepts two incompatible unescaping methods
Reproduced:
php > $fp = fopen('php://temp', 'r');
php > fputcsv($fp, array('foo', 'bar\\', 'baz'));
php > rewind($fp);
php > echo fgets($fp);
foo,"bar\",baz
php > rewind($fp);
php > var_dump(fgetcsv($fp));
array(2) {
[0]=>
string(3) "foo"
[1]=>
string(10) "bar\",baz
"
}
php > echo PHP_VERSION;
5.2.6-pl7-gentoo
php >
I believe this problem is due to the fact fgetcsv() accept two escaping methods. An extra argument
to fgetcsv() could (maybe?) fix this (and the extra argument could be added to fputcsv too)
------------------------------------------------------------------------
[2008-04-17 01:00:55] dan at expireddomain dot com
Same problem on windows XP PHP version 5.2.5 on cells that contain a \ followed by double quotes
(")
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=43225
--
Edit this bug report at https://bugs.php.net/bug.php?id=43225&edit=1