Bug #68031 [Fbk->Opn]: htmlspecialchars returns empty string, sometimes
| From: | pfenderd at bellsouth dot net | Date: | Wed, 17 Sep 2014 18:59:18 +0000 |
| Subject: | Bug #68031 [Fbk->Opn]: htmlspecialchars returns empty string, sometimes | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-187575@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=68031&edit=1
ID: 68031
User updated by: pfenderd at bellsouth dot net
Reported by: pfenderd at bellsouth dot net
Summary: htmlspecialchars returns empty string, sometimes
-Status: Feedback
+Status: Open
Type: Bug
Package: Filter related
Operating System: Linux
PHP Version: 5.5.16
Block user comment: N
Private report: N
New Comment:
As I mentioned in my original post, I got the code working by moving the variable assignment farther
down in the code, so I don't think the problem is actually with htmlspecialchars(). I have
tried to provide a section of code like the original, but there is no problem with this result.
<?php
// variable provides mock database search result of actual data that showed the problem.
$test_str = <<<XXX
Thank you for taking the time to visit us here. We would like to invite you to come and visit our
church during any of our services. We are known in the community as a friendly church where the
Bible is faithfully taught and preached.
Nothing quite compares to the joy of Christian friendship, and at God's First Church of Sample,
we make it a priority to build lasting bonds between the members of our church family - bonds of
genuine concern and commitment to one another. Best of all, this circle of care is ever widening. We
would love to include you as well.
We believe that studying the Bible is vital because it not only instructs us intellectually, but it
also guides us spiritually. We believe and accept it as God's Word to man, a book that is alive
and relevant to life today, and learning its truths can be a thrilling adventure.
Opportunities for fellowship and learning are offered to every person at every age level by our
staff of qualified teachers and leaders. We have Sunday school classes for children, youth, and
adults in which principles from the Bible are taught in an open and personal forum. In addition to
our Sunday school classes, we have a discipleship course that helps the new and even the most mature
Christian to develop a lifelong, personal, and obedient relationship with Jesus Christ through
Biblical teachings.
Just as Jesus Christ came, "not to be ministered unto, but to minister..." we accept our
responsibility to reach out in service to others. This applies both within the church family and
outside our fellowship.
Our primary reason for meeting together is to focus our attention on God, giving Him our worship,
and receiving His blessing and inspiration. Each time we meet it is a special time of spiritual
refreshment.
XXX;
$cs_info = array(
'church_subdomain_id'=>4,
'cs_subdomain'=>"sample1",
'cs_church'=>"God's First Church of Sample",
'cs_pastor'=>"Sample Simon, Pastor",
'cs_template_no'=>1,
'cs_welcome_title'=>"Welcome to God's First Church of Sample",
'cs_welcome_title2'=> '',
'cs_welcome_msg'=> $test_str,
'cs_address'=>"435 Bridge Ave",
'cs_address2'=>"",
'cs_city'=>"Sampleville",
'cs_state'=>"SC",
'cs_zip'=>"29639"
);
$rx = &$cs_info;
$church_subdomain_id = $rx['church_subdomain_id'];
$cs_subdomain = $rx['cs_subdomain'];
$cs_church = htmlspecialchars($rx['cs_church']);
$cs_pastor = htmlspecialchars($rx['cs_pastor']);
$cs_template_no = $rx['cs_template_no'];
$cs_welcome_title = htmlspecialchars($rx['cs_welcome_title']);
$cs_welcome_title2 = htmlspecialchars($rx['cs_welcome_title2']);
$cs_welcome_msg = htmlspecialchars($rx['cs_welcome_msg']);
$xcs_welcome_msg = $rx['cs_welcome_msg'];
$cs_address = htmlspecialchars($rx['cs_address']);
$cs_address2 = htmlspecialchars($rx['cs_address2']);
$cs_city = htmlspecialchars($rx['cs_city']);
$cs_state = $rx['cs_state'];
$cs_zip = $rx['cs_zip'];
// other assignments followed but no others used htmlspecialchars()
?>
<!doctype html>
<html lang="en">
<head>
<title>PHP Bug Test $2</title>
</head>
<body>
<br>
Original Variable value (<?php echo $rx['cs_welcome_msg'];?>)<br><br>
Value from htmlspecialchars() (<?php echo $cs_welcome_msg;?>)<br><br>
</body>
</html>
Previous Comments:
------------------------------------------------------------------------
[2014-09-17 17:58:38] requinix@php.net
And you have problems with *that exact script*? We need code that actually fails, not something
similar to it; start with the original code you're using and pare it down, removing database
requirements and such, until you've reached a fairly minimal version that still breaks.
For kicks, I tried running that one a few thousand times (PHP 5.5 on Ubuntu) and every single one
worked.
------------------------------------------------------------------------
[2014-09-17 17:45:21] pfenderd at bellsouth dot net
<?php
$xcs_welcome_msg = <<<XXX
Thank you for taking the time to visit us here. We would like to invite you to come and visit our
church during any of our services. We are known in the community as a friendly church where the
Bible is faithfully taught and preached.
Nothing quite compares to the joy of Christian friendship, and at God's First Church of Sample,
we make it a priority to build lasting bonds between the members of our church family - bonds of
genuine concern and commitment to one another. Best of all, this circle of care is ever widening. We
would love to include you as well.
We believe that studying the Bible is vital because it not only instructs us intellectually, but it
also guides us spiritually. We believe and accept it as God's Word to man, a book that is alive
and relevant to life today, and learning its truths can be a thrilling adventure.
Opportunities for fellowship and learning are offered to every person at every age level by our
staff of qualified teachers and leaders. We have Sunday school classes for children, youth, and
adults in which principles from the Bible are taught in an open and personal forum. In addition to
our Sunday school classes, we have a discipleship course that helps the new and even the most mature
Christian to develop a lifelong, personal, and obedient relationship with Jesus Christ through
Biblical teachings.
Just as Jesus Christ came, "not to be ministered unto, but to minister..." we accept our
responsibility to reach out in service to others. This applies both within the church family and
outside our fellowship.
Our primary reason for meeting together is to focus our attention on God, giving Him our worship,
and receiving His blessing and inspiration. Each time we meet it is a special time of spiritual
refreshment.
XXX;
$cs_welcome_msg = htmlspecialchars($xcs_welcome_msg);
?>
<!doctype html>
<html lang="en">
<head>
<title>PHP Bug Test</title>
</head>
<body>
<br>
Original Variable value (<?php echo $xcs_welcome_msg;?>)<br><br>
Value from htmlspecialchars() (<?php echo $cs_welcome_msg;?>)<br><br>
</body>
</html>
------------------------------------------------------------------------
[2014-09-17 17:41:35] requinix@php.net
Need actual source code, not just the output.
I refreshed a few times and each time it worked correctly: string was intact and unchanged (except
for a couple "s that were converted to "s).
------------------------------------------------------------------------
[2014-09-17 15:33:59] pfenderd at bellsouth dot net
The text that caused the problem was pure ASCII text and had no UTF-8 characters in it.
Test case at http://dayspeak.net/test_php_bug_htmlspecialchars.php
This simple test case failed to show the problem (worked properly).
The fact that I could work around the problem by moving the problem-causing assignment down several
lines of code indicates to me that the real problem is not in the htmlspecialchars() function itself
but in the PHP script processor.
------------------------------------------------------------------------
[2014-09-17 05:18:09] rasmus@php.net
Likely because you are getting invalid utf-8. Either specify the correct charset of your input to
your htmlspecialchars() call, or filter out invalid utf-8 before the call. Outputting invalid UTF-8
is a security risk so previous your PHP 5.3-based application was vulnerable and now it isn't.
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=68031
--
Edit this bug report at https://bugs.php.net/bug.php?id=68031&edit=1