Bug #69234 [NEW]: Escaped single quotes within double quotes not recognized
| From: | chrisdmiddleton at gmail dot com | Date: | Thu, 12 Mar 2015 22:04:04 +0000 |
| Subject: | Bug #69234 [NEW]: Escaped single quotes within double quotes not recognized | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-191357@lists.php.net to get a copy of this message | ||
From: chrisdmiddleton at gmail dot com
Operating system:
PHP version: Irrelevant
Package: *General Issues
Bug Type: Bug
Bug description:Escaped single quotes within double quotes not recognized
Description:
------------
When a single quote is backslashed within a single quote (e.g. '\''),
the result is a one-character string consisting of the single quote.
However, when the same is done within a *double*-quoted string, the
result is a two character string (\'). This behavior is unexpected,
since in every other way, double quoted strings are *more* interpretive
than single quoted strings. Furthermore, the manual
(http://php.net/manual/en/language.types.string.php#language.types.string.syntax.single)
says
> To specify a literal single quote, escape it with a backslash (\). To
specify a literal backslash, double it (\\).
> ...
> If the string is enclosed in double-quotes ("), PHP will interpret
**more** [emphasis mine] escape sequences for special characters:
> ...
> As in single quoted strings, escaping any other character will result
in the backslash being printed too. Before PHP 5.1.1, the backslash in
\{$var} had not been printed.
In my mind, this is a bug - namely, the double quoted version should
also accept escaped single quotes, since this true in most other
languages:
JavaScript
"\'" === '\'' // ==> true
Python
'\'' == "\'" // ==> true
Ruby
print "\'" == '\'' // ==> true
Perl
#!/usr/bin/perl
print "\'" == '\''; ==> 1 (true)
bash (no, but printf does)
echo "\'" # ==> \'
printf "\'" # ==> '
C/C++
#include <stdio.h>
int main (void) {
printf("\'"); // ==> '
return 0;
}
Java
public class Temp {
public static void main (String[] args) {
System.out.println("\'"); // ==> '
}
}
However, if this is a bug that has existed for a long time (and not
intentional), then changing it might break backward compatibility. In
any event, the documentation should be made *very* clear about this
issue. In my case, it was causing inappropriately quoted sql, e.g.
allowing an attack. I'm sure that many other people who assume the
behavior to be the same as in other languages might make the same
mistake.
Test script:
---------------
<?php
echo "\'";
// Expected: '
// Actual: \'
--
Edit bug report at https://bugs.php.net/bug.php?id=69234&edit=1
--
Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=69234&r=trysnapshot54
Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=69234&r=trysnapshot55
Try a snapshot (trunk): https://bugs.php.net/fix.php?id=69234&r=trysnapshottrunk
Fixed in SVN: https://bugs.php.net/fix.php?id=69234&r=fixed
Fixed in release: https://bugs.php.net/fix.php?id=69234&r=alreadyfixed
Need backtrace: https://bugs.php.net/fix.php?id=69234&r=needtrace
Need Reproduce Script: https://bugs.php.net/fix.php?id=69234&r=needscript
Try newer version: https://bugs.php.net/fix.php?id=69234&r=oldversion
Not developer issue: https://bugs.php.net/fix.php?id=69234&r=support
Expected behavior: https://bugs.php.net/fix.php?id=69234&r=notwrong
Not enough info: https://bugs.php.net/fix.php?id=69234&r=notenoughinfo
Submitted twice: https://bugs.php.net/fix.php?id=69234&r=submittedtwice
register_globals: https://bugs.php.net/fix.php?id=69234&r=globals
PHP 4 support discontinued: https://bugs.php.net/fix.php?id=69234&r=php4
Daylight Savings: https://bugs.php.net/fix.php?id=69234&r=dst
IIS Stability: https://bugs.php.net/fix.php?id=69234&r=isapi
Install GNU Sed: https://bugs.php.net/fix.php?id=69234&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=69234&r=float
No Zend Extensions: https://bugs.php.net/fix.php?id=69234&r=nozend
MySQL Configuration Error: https://bugs.php.net/fix.php?id=69234&r=mysqlcfg