Bug #67055 [Opn->Nab]: output of json_encode does not comply with the definition

From: Date: Fri, 25 Apr 2014 16:51:43 +0000
Subject: Bug #67055 [Opn->Nab]: output of json_encode does not comply with the definition
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-185444@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=67055&edit=1 ID: 67055 Updated by: aharvey@php.net Reported by: mail+bugs dot php dot net at kazik dot de Summary: output of json_encode does not comply with the definition -Status: Open +Status: Not a bug Type: Bug Package: JSON related Operating System: All PHP Version: Irrelevant Block user comment: N Private report: N New Comment: Yep; this is correct per the JSON spec. Previous Comments: ------------------------------------------------------------------------ [2014-04-25 01:22:05] pleasestand at live dot com > The function json_encode does not encode strings accordingly to the json definition. In RFC 7159, section "7. Strings" defines the "control characters" as only "U+0000 through U+001F". More specifically, the characters you mention are explicitly allowed to be left unescaped: unescaped = %x20-21 / %x23-5B / %x5D-10FFFF Note that JavaScript's JSON.stringify() doesn't escape "\u007f" either. ------------------------------------------------------------------------ [2014-04-10 12:50:58] mail+bugs dot php dot net at kazik dot de Description: ------------ The function json_encode does not encode strings accordingly to the json definition. It affects at least php since 5.3.28 up to the latest version (currently 5.5.11). According to the definition a string may not contain a quote, slash or control character. Control characters are the c0 set (0x00-0x1f), delete (0x7f) and the c1 set (0x80-0x9f) (see http://en.wikipedia.org/wiki/Unicode_control_characters). Source: ext/json/json.c, function json_escape_string The function only checks for the c0 set but does not handle delete and the c1 set correctly. The c1 set bug is only affected with the option JSON_UNESCAPED_UNICODE (since php 5.4.0). Test script: --------------- echo json_encode(chr(0x7f)).PHP_EOL; echo json_encode(chr(0xc2).chr(0x80)), JSON_UNESCAPED_UNICODE).PHP_EOL; // the utf8 representation of \u0080 Expected result: ---------------- "\u007f" "\u0080" Actual result: -------------- '"'.chr(0x7f).'"' '"'.chr(0xc2).chr(0x80).'"' // the utf8 representation of /u0080 ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=67055&edit=1

« previous php.bugs (#185444) next »