Bug #68546 [ReO]: json_decode() Fatal error: Cannot access property started with '\0'
| From: | yohgaki@php.net | Date: | Fri, 05 Dec 2014 03:08:31 +0000 |
| Subject: | Bug #68546 [ReO]: json_decode() Fatal error: Cannot access property started with '\0' | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-188922@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=68546&edit=1
ID: 68546
Updated by: yohgaki@php.net
Reported by: j dot tvr at centrum dot cz
Summary: json_decode() Fatal error: Cannot access property
started with '\0'
Status: Re-Opened
Type: Bug
Package: JSON related
PHP Version: 5.6.3
Block user comment: N
Private report: N
New Comment:
I'm not sure current implementation, but RFC 7259 defines "string" as
http://tools.ietf.org/html/rfc7159#page-5
string = quotation-mark *char quotation-mark
char = unescaped /
escape (
%x22 / ; " quotation mark U+0022
%x5C / ; \ reverse solidus U+005C
%x2F / ; / solidus U+002F
%x62 / ; b backspace U+0008
%x66 / ; f form feed U+000C
%x6E / ; n line feed U+000A
%x72 / ; r carriage return U+000D
%x74 / ; t tab U+0009
%x75 4HEXDIG ) ; uXXXX U+XXXX
escape = %x5C ; \
quotation-mark = %x22 ; "
unescaped = %x20-21 / %x23-5B / %x5D-10FFFF
Anything other than this spec should result in error. i.e. NULL
It would be depended on underlying library, though.
Previous Comments:
------------------------------------------------------------------------
[2014-12-05 03:00:32] yohgaki@php.net
<?php
var_dump(json_decode('{"a": 1}'));
var_dump(json_decode('{"1": 1}'));
var_dump(json_decode('{a: 1, "a": 1}')); // invalid JSON
var_dump(json_decode('{"a\u0000b: 1}')); // invalid JSON
?>
http://3v4l.org/nncBo
E_WARNING may be too much. Just returning NULL seems to be enough and leave users to handle errors.
------------------------------------------------------------------------
[2014-12-05 02:41:45] yohgaki@php.net
http://3v4l.org/imJSu
I agree that this should not result in E_ERROR. Ignoring offensive data and raise E_WARNING is
nicer.
------------------------------------------------------------------------
[2014-12-05 01:54:01] requinix@php.net
Ah, sorry, I forgot that json is an awkward extension with multiple underlying implementations. I
was using jsonc on Ubuntu where it worked, but it does fail on Windows.
Given that JSON is often passed as user input, I'd really like it if I could decode strings
without worrying about fatal errors and continue with my input validation normally.
------------------------------------------------------------------------
[2014-12-04 23:42:18] aharvey@php.net
It does fail for me in the json_decode as well, although I'm _very_ on the fence about whether
this is actually worth fixing.
------------------------------------------------------------------------
[2014-12-04 22:57:16] j dot tvr at centrum dot cz
That code does NOT work fine, it is a bug in ext-json. Both jsonc
(http://pecl.php.net/package/jsonc) and jsond (http://pecl.php.net/package/jsond) do not result in
fatal error for the very same input.
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=68546
--
Edit this bug report at https://bugs.php.net/bug.php?id=68546&edit=1