Edit report at https://bugs.php.net/bug.php?id=43225&edit=1
ID: 43225
Comment by: maris dot radu+phpnet at gmail dot com
Reported by: ed at bronto dot com
Summary: fputcsv incorrectly handles cells ending in \
followed by "
Status: Re-Opened
Type: Bug
Package: Filesystem function related
Operating System: Centos
PHP Version: 5.2.4
Block user comment: N
Private report: N
New Comment:
Just not to confuse people, aharvey@php.net said it's fixed in "5.3.22 and 5.4.12",
but in fact I tested in 5.4.31 and it's not fixed.
Looking at the patch commit it seems it's tagged with php-5.6.0beta4, so I guess will only be
available in 5.6.
Previous Comments:
------------------------------------------------------------------------
[2013-01-15 09:43:18] aharvey@php.net
Sadly, that was a classic case of fixing one thing and breaking another. Reopening, and unassigning
myself.
------------------------------------------------------------------------
[2013-01-15 07:35:00] aharvey@php.net
Fixed in 5.3.22 and 5.4.12: https://github.com/php/php-src/commit/9b5cb0e8059b1e8bec096067491ed8d75f878938
------------------------------------------------------------------------
[2013-01-15 07:05:38] aharvey@php.net
I've found the cause of this while writing tests for PR 197.
php_fputcsv(), while iterating over the fields to be output, has this fairly odd "escaped"
concept â once escape_char (which is hardcoded \ at present) is seen, escaping stops until the
next enclosure (" by default) is seen. It doesn't matter whether it's the following
character or not.
After that, escape_char is then ignored anyway, and the enclosure is used as the "escape"
character.
This came in via https://github.com/php/php-src/commit/af0adbed3963cdee1bfaf5e3a74b029d2b92c8b7
seven years ago to make the use of enclosures optional â the feature in general is good, but
this is definitely an issue in the implementation.
------------------------------------------------------------------------
[2009-10-09 19:57:18] mbest at icontact dot com
magicaltux@php.net is wrong. This bug is not about fgetcsv but about fputcsv. fputcsv should
always escape a double quote to two double quotes. But it doesn't do so if the field contains
\" This will mess up the CSV output such that it will not be importable in Excel or other such
programs.
------------------------------------------------------------------------
[2009-01-19 12:54:38] magicaltux@php.net
This bug is the same as bug #38918 and bug #38929.
* fputcsv() does escape values (replacing " with "", for example)
* It seems that fgetcsv() accepts two incompatible unescaping methods
Reproduced:
php > $fp = fopen('php://temp', 'r');
php > fputcsv($fp, array('foo', 'bar\\', 'baz'));
php > rewind($fp);
php > echo fgets($fp);
foo,"bar\",baz
php > rewind($fp);
php > var_dump(fgetcsv($fp));
array(2) {
[0]=>
string(3) "foo"
[1]=>
string(10) "bar\",baz
"
}
php > echo PHP_VERSION;
5.2.6-pl7-gentoo
php >
I believe this problem is due to the fact fgetcsv() accept two escaping methods. An extra argument
to fgetcsv() could (maybe?) fix this (and the extra argument could be added to fputcsv too)
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=43225
--
Edit this bug report at https://bugs.php.net/bug.php?id=43225&edit=1