Bug #69234 [NEW]: Escaped single quotes within double quotes not recognized

From: Date: Thu, 12 Mar 2015 22:04:04 +0000
Subject: Bug #69234 [NEW]: Escaped single quotes within double quotes not recognized
Groups: php.bugs 
Request: Send a blank email to php-bugs+get-191357@lists.php.net to get a copy of this message
From: chrisdmiddleton at gmail dot com Operating system: PHP version: Irrelevant Package: *General Issues Bug Type: Bug Bug description:Escaped single quotes within double quotes not recognized Description: ------------ When a single quote is backslashed within a single quote (e.g. '\''), the result is a one-character string consisting of the single quote. However, when the same is done within a *double*-quoted string, the result is a two character string (\'). This behavior is unexpected, since in every other way, double quoted strings are *more* interpretive than single quoted strings. Furthermore, the manual (http://php.net/manual/en/language.types.string.php#language.types.string.syntax.single) says > To specify a literal single quote, escape it with a backslash (\). To specify a literal backslash, double it (\\). > ... > If the string is enclosed in double-quotes ("), PHP will interpret **more** [emphasis mine] escape sequences for special characters: > ... > As in single quoted strings, escaping any other character will result in the backslash being printed too. Before PHP 5.1.1, the backslash in \{$var} had not been printed. In my mind, this is a bug - namely, the double quoted version should also accept escaped single quotes, since this true in most other languages: JavaScript "\'" === '\'' // ==> true Python '\'' == "\'" // ==> true Ruby print "\'" == '\'' // ==> true Perl #!/usr/bin/perl print "\'" == '\''; ==> 1 (true) bash (no, but printf does) echo "\'" # ==> \' printf "\'" # ==> ' C/C++ #include <stdio.h> int main (void) { printf("\'"); // ==> ' return 0; } Java public class Temp { public static void main (String[] args) { System.out.println("\'"); // ==> ' } } However, if this is a bug that has existed for a long time (and not intentional), then changing it might break backward compatibility. In any event, the documentation should be made *very* clear about this issue. In my case, it was causing inappropriately quoted sql, e.g. allowing an attack. I'm sure that many other people who assume the behavior to be the same as in other languages might make the same mistake. Test script: --------------- <?php echo "\'"; // Expected: ' // Actual: \' -- Edit bug report at https://bugs.php.net/bug.php?id=69234&edit=1 -- Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=69234&r=trysnapshot54 Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=69234&r=trysnapshot55 Try a snapshot (trunk): https://bugs.php.net/fix.php?id=69234&r=trysnapshottrunk Fixed in SVN: https://bugs.php.net/fix.php?id=69234&r=fixed Fixed in release: https://bugs.php.net/fix.php?id=69234&r=alreadyfixed Need backtrace: https://bugs.php.net/fix.php?id=69234&r=needtrace Need Reproduce Script: https://bugs.php.net/fix.php?id=69234&r=needscript Try newer version: https://bugs.php.net/fix.php?id=69234&r=oldversion Not developer issue: https://bugs.php.net/fix.php?id=69234&r=support Expected behavior: https://bugs.php.net/fix.php?id=69234&r=notwrong Not enough info: https://bugs.php.net/fix.php?id=69234&r=notenoughinfo Submitted twice: https://bugs.php.net/fix.php?id=69234&r=submittedtwice register_globals: https://bugs.php.net/fix.php?id=69234&r=globals PHP 4 support discontinued: https://bugs.php.net/fix.php?id=69234&r=php4 Daylight Savings: https://bugs.php.net/fix.php?id=69234&r=dst IIS Stability: https://bugs.php.net/fix.php?id=69234&r=isapi Install GNU Sed: https://bugs.php.net/fix.php?id=69234&r=gnused Floating point limitations: https://bugs.php.net/fix.php?id=69234&r=float No Zend Extensions: https://bugs.php.net/fix.php?id=69234&r=nozend MySQL Configuration Error: https://bugs.php.net/fix.php?id=69234&r=mysqlcfg

« previous php.bugs (#191357) next »