Bug #62683 [Opn->Csd]: FILTER_SANITIZE_SPECIAL_CHARS does not work as declared

From: Date: Mon, 13 Jan 2014 01:39:39 +0000
Subject: Bug #62683 [Opn->Csd]: FILTER_SANITIZE_SPECIAL_CHARS does not work as declared
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-183741@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=62683&edit=1 ID: 62683 Updated by: requinix@php.net Reported by: admin dot windows at gmail dot com Summary: FILTER_SANITIZE_SPECIAL_CHARS does not work as declared -Status: Open +Status: Closed Type: Bug Package: Filter related Operating System: Windows/Linux PHP Version: 5.3.15 -Assigned To: +Assigned To: requinix Block user comment: N Private report: N New Comment: Thank you for your bug report. This issue has already been fixed in the latest released version of PHP, which you can download at http://www.php.net/downloads.php Previous Comments: ------------------------------------------------------------------------ [2014-01-13 00:51:27] shensiapoost at yahoo dot com According to http://www.php.net/manual/en/filter.filters.sanitize.php, only FILTER_SANITIZE_FULL_SPECIAL_CHARS is equal to htmlspecialchars(). Therefore, FILTER_SANITIZE_SPECIAL_CHARS is acting like it should. The reason you are seeing FILTER_SANITIZE_FULL_SPECIAL_CHARS not produce the right results is because of https://bugs.php.net/bug.php?id=65282. Because of this bug, if you used the FILTER_SANITIZE_FULL_SPECIAL_CHARS constant, you were essentially calling FILTER_SANITIZE_SPECIAL_CHARS. Thus, why the two produce the same result. ------------------------------------------------------------------------ [2012-07-28 12:22:16] admin dot windows at gmail dot com Description: ------------ FILTER_SANITIZE_SPECIAL_CHARS and FILTER_SANITIZE_FULL_SPECIAL_CHARS does not work as documented and produced results does not match htmlspecialchars results at all. Test script: --------------- $string = "<a href=\"#\">O'Reilly - PHP Tips & Tricks</a>"; //string '<a href="#">O'Reilly - PHP Tips & Tricks</a>' (length=44) var_dump($string); //string '&lt;a href=&quot;#&quot;&gt;O&#039;Reilly - PHP Tips &amp; Tricks&lt;/a&gt;' (length=75) var_dump(htmlspecialchars($string, ENT_QUOTES)); //string '&#60;a href=&#34;#&#34;&#62;O&#39;Reilly - PHP Tips &#38; Tricks&#60;/a&#62;' (length=76) var_dump(filter_var($string, FILTER_SANITIZE_SPECIAL_CHARS)); //string '&#60;a href=&#34;#&#34;&#62;O&#39;Reilly - PHP Tips &#38; Tricks&#60;/a&#62;' (length=76) var_dump(filter_var($string, FILTER_SANITIZE_FULL_SPECIAL_CHARS)); Expected result: ---------------- //string '&lt;a href=&quot;#&quot;&gt;O&#039;Reilly - PHP Tips &amp; Tricks&lt;/a&gt;' (length=75) Actual result: -------------- //string '&#60;a href=&#34;#&#34;&#62;O&#39;Reilly - PHP Tips &#38; Tricks&#60;/a&#62;' (length=76) ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=62683&edit=1

« previous php.bugs (#183741) next »