Bug #43225 [Com]: fputcsv incorrectly handles cells ending in \ followed by "

From: Date: Thu, 21 Aug 2014 23:55:58 +0000
Subject: Bug #43225 [Com]: fputcsv incorrectly handles cells ending in \ followed by "
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-187229@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=43225&edit=1

 ID:                 43225
 Comment by:         maris dot radu+phpnet at gmail dot com
 Reported by:        ed at bronto dot com
 Summary:            fputcsv incorrectly handles cells ending in \
                     followed by "
 Status:             Re-Opened
 Type:               Bug
 Package:            Filesystem function related
 Operating System:   Centos
 PHP Version:        5.2.4
 Block user comment: N
 Private report:     N

 New Comment:

Just not to confuse people, aharvey@php.net said it's fixed in "5.3.22 and 5.4.12",
but in fact I tested in 5.4.31 and it's not fixed.

Looking at the patch commit it seems it's tagged with php-5.6.0beta4, so I guess will only be
available in 5.6.


Previous Comments:
------------------------------------------------------------------------
[2013-01-15 09:43:18] aharvey@php.net

Sadly, that was a classic case of fixing one thing and breaking another. Reopening, and unassigning
myself.

------------------------------------------------------------------------
[2013-01-15 07:35:00] aharvey@php.net

Fixed in 5.3.22 and 5.4.12: https://github.com/php/php-src/commit/9b5cb0e8059b1e8bec096067491ed8d75f878938

------------------------------------------------------------------------
[2013-01-15 07:05:38] aharvey@php.net

I've found the cause of this while writing tests for PR 197.

php_fputcsv(), while iterating over the fields to be output, has this fairly odd "escaped"
concept — once escape_char (which is hardcoded \ at present) is seen, escaping stops until the
next enclosure (" by default) is seen. It doesn't matter whether it's the following
character or not.

After that, escape_char is then ignored anyway, and the enclosure is used as the "escape"
character.

This came in via https://github.com/php/php-src/commit/af0adbed3963cdee1bfaf5e3a74b029d2b92c8b7
seven years ago to make the use of enclosures optional — the feature in general is good, but
this is definitely an issue in the implementation.

------------------------------------------------------------------------
[2009-10-09 19:57:18] mbest at icontact dot com

magicaltux@php.net is wrong.  This bug is not about fgetcsv but about fputcsv.  fputcsv should
always escape a double quote to two double quotes. But it doesn't do so if the field contains
\"  This will mess up the CSV output such that it will not be importable in Excel or other such
programs.

------------------------------------------------------------------------
[2009-01-19 12:54:38] magicaltux@php.net

This bug is the same as bug #38918 and bug #38929.

* fputcsv() does escape values (replacing " with "", for example)
* It seems that fgetcsv() accepts two incompatible unescaping methods

Reproduced:
php > $fp = fopen('php://temp', 'r');
php > fputcsv($fp, array('foo', 'bar\\', 'baz'));
php > rewind($fp);
php > echo fgets($fp);
foo,"bar\",baz
php > rewind($fp);
php > var_dump(fgetcsv($fp));
array(2) {
  [0]=>
  string(3) "foo"
  [1]=>
  string(10) "bar\",baz
"
}
php > echo PHP_VERSION;
5.2.6-pl7-gentoo
php > 

I believe this problem is due to the fact fgetcsv() accept two escaping methods. An extra argument
to fgetcsv() could (maybe?) fix this (and the extra argument could be added to fputcsv too)

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=43225


--
Edit this bug report at https://bugs.php.net/bug.php?id=43225&edit=1


Thread (15 messages)

« previous php.bugs (#187229) next »