Bug #69140 [Com]: FILTER_VALIDATE_EMAIL not RFC 822 compliant

From: Date: Mon, 02 Mar 2015 00:16:22 +0000
Subject: Bug #69140 [Com]: FILTER_VALIDATE_EMAIL not RFC 822 compliant
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-191031@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=69140&edit=1

 ID:                 69140
 Comment by:         ppaisndud at gmail dot com
 Reported by:        info at linux-web-development dot de
 Summary:            FILTER_VALIDATE_EMAIL not RFC 822 compliant
 Status:             Open
 Type:               Bug
 Package:            Filter related
 PHP Version:        Irrelevant
 Block user comment: N
 Private report:     N

 New Comment:

I did a bit of fixing and this could be a patch, strict to RFC 822 

https://github.com/pasindud/php-src/commit/ec209d5add25322122e10e18261f0ae5fa7a57cf

Some Issuses

RFC 822 - is obsolete in 2001 by 2822, 5322
RFC 2822 - is obsolete in 2008 by 5322,5321 (both of those also have conflicts)


Previous Comments:
------------------------------------------------------------------------
[2015-03-01 18:18:10] info at linux-web-development dot de

The docs are still not correct. The PHP validation is just wrong in more ways than just comments.
e.g. the domain part could be a hostname without a dot, but this always comes back as false. This
has real applications, e.g. under Linux when sending to [user]@localhost

There is a reason frameworks don't use this built-in function but instead resort to their own
validation for e-mails. So this function should either be clearly marked as non-RFC-compatible or
just work as one would expect it to work. Sorry, but not fixing this because it's hard to
implement is just a lame excuse. Implement it or leave it out, but don't implement some
half-working frankenvalidation.

------------------------------------------------------------------------
[2015-02-27 20:50:05] aharvey@php.net

Automatic comment from SVN on behalf of aharvey
Revision: http://svn.php.net/viewvc/?view=revision&revision=336016
Log: Expand on what FILTER_VALIDATE_EMAIL really validates.

See also bug #69140 (FILTER_VALIDATE_EMAIL not RFC 822 compliant).

------------------------------------------------------------------------
[2015-02-27 20:46:26] aharvey@php.net

The code does actually document that comments aren't handled, but that never made it to the
docs. I'll fix that.

I don't think this is worth fixing (the validation code is terrifying enough as it is, and,
seriously, comments in e-mail addresses?), but I'll leave this open in case someone can provide
a clean PR.

------------------------------------------------------------------------
[2015-02-27 17:02:32] info at linux-web-development dot de

Description:
------------
When trying to validate an e-mail address using FILTER_VALIDATE_EMAIL will result in several
problems with correct mail addresses. So far I could find the following compliant addresses not
validating:

foo@example
foo@(bar)example.com
foo@example.com(bar)

Generally PHP should at comply with RFC 822 when validating mail addresses, otherwise the filter
function is useless.

Test script:
---------------
var_dump(filter_var('foo@example', FILTER_VALIDATE_EMAIL));

Expected result:
----------------
string(11) "foo@example"


Actual result:
--------------
bool(false)


------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=69140&edit=1


Thread (7 messages)

« previous php.bugs (#191031) next »