Edit report at https://bugs.php.net/bug.php?id=69409&edit=1
ID: 69409
User updated by: rainer-phpbugs at 7val dot com
Reported by: rainer-phpbugs at 7val dot com
Summary: urlencode() does not conform to current w3 html5
recommendations
Status: Open
Type: Feature/Change Request
Package: URL related
Operating System: all
PHP Version: 5.6.7
Block user comment: N
Private report: N
New Comment:
Sadly, rawurlencode() doesn't comply with another part of the HTML 5 recommendation:
If the byte is 0x20 (U+0020 SPACE if interpreted as ASCII)
Replace the byte with a single 0x2B byte ("+" (U+002B) character if interpreted as
ASCII).
http://3v4l.org/q8p9i
print("rue: ".rawurlencode(' ')."\n");
print("ue: ".urlencode(' ')."\n");
rue: %20
ue: +
I sincerely hope that no third encoding function is necessary.
Previous Comments:
------------------------------------------------------------------------
[2015-04-14 20:45:15] yohgaki@php.net
urlencode() is there for compatibility. rawurlencode() does the jobs.
http://3v4l.org/L0AHV
We shouldn't have 2 similar functions in the first place, probably...
Consolidate 2 functions into one (urlencode) by having mode flag in the long run?
http_build_query() has the same issue, but it has flag for modes.
------------------------------------------------------------------------
[2015-04-09 16:35:29] rainer-phpbugs at 7val dot com
Description:
------------
---
From manual page: http://www.php.net/function.urlencode
---
urlencode() does not conform to then current w3 html5 recommendations for
application/x-www-form-urlencoded data, in that '*' (0x2A) should be left as is.
http://www.w3.org/TR/html5/forms.html#application/x-www-form-urlencoded-encoding-algorithm
If the byte is in the range 0x2A [...] Leave the byte as is.
rfc3986 would also allow '*' to be left unchangef in the query part of an URL.
http://tools.ietf.org/html/rfc3986
query = *( pchar / "/" / "?" )
pchar = unreserved / pct-encoded / sub-delims / ":" / "@"
sub-delims = "!" / "$" / "&" / "'" /
"(" / ")"
/ "*" / "+" / "," / ";" / "="
Test script:
---------------
<?php
print(urlencode('*'));
Expected result:
----------------
'*' should not be %-encoded, i.e. the test script above should not print %2A, but the
literal '*'.
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=69409&edit=1