Bug #69203 [Csd]: FILTER_FLAG_STRIP_HIGH doesn't strip ASCII 127
| From: | derick@php.net | Date: | Tue, 21 Apr 2015 10:44:57 +0000 |
| Subject: | Bug #69203 [Csd]: FILTER_FLAG_STRIP_HIGH doesn't strip ASCII 127 | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-192255@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=69203&edit=1
ID: 69203
Updated by: derick@php.net
Reported by: whatthejeff@php.net
Summary: FILTER_FLAG_STRIP_HIGH doesn't strip ASCII 127
Status: Closed
Type: Bug
Package: Filter related
PHP Version: 5.5Git-2015-03-09 (Git)
Assigned To: whatthejeff
Block user comment: N
Private report: N
New Comment:
BTW, that's what the docs say too: http://docs.php.net/manual/en/filter.filters.flags.php
Previous Comments:
------------------------------------------------------------------------
[2015-04-21 08:56:12] derick@php.net
IIRC, they should strip / encode for for >= 128 only.
------------------------------------------------------------------------
[2015-04-21 08:23:59] whatthejeff@php.net
> So it seems like an unintentional side-effect. Until then, both STRIP and ENCODE were for
> >127.
I think there was only one PHP release that included this extension before that commit. Hard to say
if it was intentional or not, but I guess we could ask Derick or Ilia if they remember.
My assumption is that these flags were intended to optionally strip/encode characters that
don't fall within the range of printable ASCII characters (20-7e). It's true that the
original code didn't strip/encode the DEL control character (7f), but I'm not sure if that
was intentional or an oversight.
------------------------------------------------------------------------
[2015-04-20 14:04:45] dominic at mailinator dot com
It looks like FILTER_FLAG_ENCODE_HIGH's behaviour changed in commit: http://git.php.net/?p=php-src.git;a=commit;h=7d7248390cb85f61150304bbdd3eace0a2023a86
with message:
Filter fixes:
Fixed possible double encoding problem with sanitizing filters
Make use of space-strict strip_tags() function
So it seems like an unintentional side-effect. Until then, both STRIP and ENCODE were for >127.
------------------------------------------------------------------------
[2015-04-20 12:25:49] dominic at mailinator dot com
That's a little confusing. Lots of people mean Extended ASCII when they refer to ASCII.
Extended ASCII encodes 256 characters, with the additional 128 characters known as 'High
ASCII'.
Given that the PHP documentation - http://php.net/manual/en/filter.filters.flags.php
- says that these filters encode/strip characters higher than 127 (which is now no longer true?), I
suspect the filter creators and the documenters were referring to High ASCII.
------------------------------------------------------------------------
[2015-04-20 12:03:57] whatthejeff@php.net
ASCII only encodes 128 characters. I think LOW/HIGH was meant to reference the non-printable
characters.
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=69203
--
Edit this bug report at https://bugs.php.net/bug.php?id=69203&edit=1