Bug #68129 [Opn->Csd]: parse_url() - incomplete support for empty usernames and passwords

From: Date: Thu, 09 Oct 2014 00:27:23 +0000
Subject: Bug #68129 [Opn->Csd]: parse_url() - incomplete support for empty usernames and passwords
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-187967@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=68129&edit=1 ID: 68129 Updated by: datibbaw@php.net Reported by: vort dot fu at gmail dot com Summary: parse_url() - incomplete support for empty usernames and passwords -Status: Open +Status: Closed Type: Bug Package: URL related Operating System: OS X 10.9.5 PHP Version: 5.6.0 Block user comment: N Private report: N New Comment: Automatic comment on behalf of datibbaw Revision: http://git.php.net/?p=php-src.git;a=commit;h=d0e51f5ce992ab5fc90c4d962a5d4e8c24b74823 Log: Fixed bug #68129 Previous Comments: ------------------------------------------------------------------------ [2014-10-02 00:58:06] vort dot fu at gmail dot com Description: ------------ Section 3.1 "Common Internet Scheme Syntax" of RFC-1738 "Uniform Resource Locators (URL)" (https://www.ietf.org/rfc/rfc1738.txt) states the following: Note that an empty user name or password is different than no user name or password; there is no way to specify a password without specifying a user name. E.g., <URL:ftp://@host.com/> has an empty user name and no password, <URL:ftp://host.com/> has no user name, while <URL:ftp://foo:@host.com/> has a user name of "foo" and an empty password. parse_url() currently only supports empty user names if a password component is not specified (including empty passwords, which aren't supported at all) Test script: --------------- <?php // correct (returns empty username) var_dump( parse_url( 'https://@example.com' ) ); // incorrect (doesn't return empty username or password) var_dump( parse_url( 'https://:@example.com' ) ); // incorrect (doesn't return empty username) var_dump( parse_url( 'https://:password@example.com' ) ); // incorrect (doesn't return empty password) var_dump( parse_url( 'https://username:@example.com' ) ); Expected result: ---------------- array(3) { ["scheme"]=> string(5) "https" ["host"]=> string(11) "example.com" ["user"]=> string(0) "" } array(4) { ["scheme"]=> string(5) "https" ["host"]=> string(11) "example.com" ["user"]=> string(0) "" ["pass"]=> string(0) "" } array(4) { ["scheme"]=> string(5) "https" ["host"]=> string(11) "example.com" ["user"]=> string(0) "" ["pass"]=> string(8) "password" } array(4) { ["scheme"]=> string(5) "https" ["host"]=> string(11) "example.com" ["user"]=> string(8) "username" ["pass"]=> string(0) "" } Actual result: -------------- array(3) { ["scheme"]=> string(5) "https" ["host"]=> string(11) "example.com" ["user"]=> string(0) "" } array(2) { ["scheme"]=> string(5) "https" ["host"]=> string(11) "example.com" } array(3) { ["scheme"]=> string(5) "https" ["host"]=> string(11) "example.com" ["pass"]=> string(8) "password" } array(3) { ["scheme"]=> string(5) "https" ["host"]=> string(11) "example.com" ["user"]=> string(8) "username" } ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=68129&edit=1

« previous php.bugs (#187967) next »