Bug #66682 [Nab]: FILTER_VALIDATE_INT fails on strings starting with zero.
| From: | yohgaki@php.net | Date: | Sun, 16 Feb 2014 21:57:21 +0000 |
| Subject: | Bug #66682 [Nab]: FILTER_VALIDATE_INT fails on strings starting with zero. | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-184328@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=66682&edit=1
ID: 66682
Updated by: yohgaki@php.net
Reported by: alex dot howansky at gmail dot com
Summary: FILTER_VALIDATE_INT fails on strings starting with
zero.
Status: Not a bug
Type: Bug
Package: Filter related
Operating System: Linux 2.6 64
PHP Version: 5.5.9
Block user comment: N
Private report: N
New Comment:
Hi Derick,
I'm not sure if this behavior is documented somewhere, but it seems strange. Tests do not cover
"01.23" nor "01" also, for example. I found this note http://jp2.php.net/manual/en/filter.filters.validate.php
but nothing else.
Note:
As of PHP 5.4.11, the numbers +0 and -0 validate as both integers as well as floats (using
FILTER_VALIDATE_FLOAT and FILTER_VALIDATE_INT). Before PHP 5.4.11 they only validated as floats
(using FILTER_VALIDATE_FLOAT).
When default is set to option, default's value is used if value is not validated.
If we are not going to fix this, this behavior should be documented if it's not already there.
So make this a documentation problem?
BTW, I haven't test much, but the patch in github invalidates "01",
"01.123", etc.
Previous Comments:
------------------------------------------------------------------------
[2014-02-16 21:38:26] alex dot howansky at gmail dot com
OK, understood. Unfortunately, this leaves an odd hole when working with strings that start with
zero and contain an eight or nine. For example, intval() only performs octal validation if you
explicitly override the base parameter's default value of 10. As a result,
intval('09') gives you exactly what you'd expect -- int(9). Likewise, '09'
+ 1 works just as expected, in base 10. However, regardless of flags, FILTER_VALIDATE_INT can never
return true for string '09'. Given that '09' is perfectly acceptable input for
other cases which require an int, this seems inconsistent. Perhaps a new option should be added to
this filter, named "base" or similar, which functions like the optional "base"
argument of intval().
------------------------------------------------------------------------
[2014-02-16 19:17:39] rasmus@php.net
By definition an integer with a leading zero is octal notation so 00 is octal 0. There is a flag to
explicitly allow octal integers which should also tell you that validate_int validates integers
written in decimal notation by default.
------------------------------------------------------------------------
[2014-02-16 18:52:55] alex dot howansky at gmail dot com
Also, consider this:
var_dump(filter_var('0', FILTER_VALIDATE_INT));
var_dump(filter_var('00', FILTER_VALIDATE_INT));
Returns:
int(0)
bool(false)
That's incredibly counter-intuitive.
------------------------------------------------------------------------
[2014-02-16 16:23:03] alex dot howansky at gmail dot com
> Please double-check the documentation
I'm unable to find any documentation that contradicts my evaluation or explains this behavior.
Can you please link to the specific page you're referring to?
I'm confused by the hex/oct comment -- whether or not "01" is interpreted as octal or
hex doesn't change the fact that it's still a valid value for an integer. I.e.,
"01" octal is a valid int, "01" hex is a valid int, and "01" decimal
is a valid int.
Also, if I plug "01" into any other function that expects an integer, it will work just
fine. Consider this:
var_dump(abs('01'));
var_dump(intval('01'));
var_dump(octdec('01'));
var_dump(hexdec('01'));
var_dump(filter_var('01' + '0.0', FILTER_VALIDATE_INT));
var_dump(filter_var('01', FILTER_VALIDATE_INT));
Returns:
int(1)
int(1)
int(1)
int(1)
int(1)
bool(false)
Don't you think that output is rather contradictory?
------------------------------------------------------------------------
[2014-02-16 11:55:43] derick@php.net
Thank you for taking the time to write to us, but this is not
a bug. Please double-check the documentation available at
http://www.php.net/manual/ and the instructions on how to
report
a bug at http://bugs.php.net/how-to-report.php
This is by design.
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=66682
--
Edit this bug report at https://bugs.php.net/bug.php?id=66682&edit=1