Bug #69203 [Csd]: FILTER_FLAG_STRIP_HIGH doesn't strip ASCII 127

From: Date: Tue, 21 Apr 2015 10:44:57 +0000
Subject: Bug #69203 [Csd]: FILTER_FLAG_STRIP_HIGH doesn't strip ASCII 127
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-192255@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=69203&edit=1 ID: 69203 Updated by: derick@php.net Reported by: whatthejeff@php.net Summary: FILTER_FLAG_STRIP_HIGH doesn't strip ASCII 127 Status: Closed Type: Bug Package: Filter related PHP Version: 5.5Git-2015-03-09 (Git) Assigned To: whatthejeff Block user comment: N Private report: N New Comment: BTW, that's what the docs say too: http://docs.php.net/manual/en/filter.filters.flags.php Previous Comments: ------------------------------------------------------------------------ [2015-04-21 08:56:12] derick@php.net IIRC, they should strip / encode for for >= 128 only. ------------------------------------------------------------------------ [2015-04-21 08:23:59] whatthejeff@php.net > So it seems like an unintentional side-effect. Until then, both STRIP and ENCODE were for > >127. I think there was only one PHP release that included this extension before that commit. Hard to say if it was intentional or not, but I guess we could ask Derick or Ilia if they remember. My assumption is that these flags were intended to optionally strip/encode characters that don't fall within the range of printable ASCII characters (20-7e). It's true that the original code didn't strip/encode the DEL control character (7f), but I'm not sure if that was intentional or an oversight. ------------------------------------------------------------------------ [2015-04-20 14:04:45] dominic at mailinator dot com It looks like FILTER_FLAG_ENCODE_HIGH's behaviour changed in commit: http://git.php.net/?p=php-src.git;a=commit;h=7d7248390cb85f61150304bbdd3eace0a2023a86 with message: Filter fixes: Fixed possible double encoding problem with sanitizing filters Make use of space-strict strip_tags() function So it seems like an unintentional side-effect. Until then, both STRIP and ENCODE were for >127. ------------------------------------------------------------------------ [2015-04-20 12:25:49] dominic at mailinator dot com That's a little confusing. Lots of people mean Extended ASCII when they refer to ASCII. Extended ASCII encodes 256 characters, with the additional 128 characters known as 'High ASCII'. Given that the PHP documentation - http://php.net/manual/en/filter.filters.flags.php - says that these filters encode/strip characters higher than 127 (which is now no longer true?), I suspect the filter creators and the documenters were referring to High ASCII. ------------------------------------------------------------------------ [2015-04-20 12:03:57] whatthejeff@php.net ASCII only encodes 128 characters. I think LOW/HIGH was meant to reference the non-printable characters. ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=69203 -- Edit this bug report at https://bugs.php.net/bug.php?id=69203&edit=1

« previous php.bugs (#192255) next »