Bug #69203 [Com]: FILTER_FLAG_STRIP_HIGH doesn't strip ASCII 127
| From: | whatthejeff@php.net | Date: | Tue, 21 Apr 2015 11:16:35 +0000 |
| Subject: | Bug #69203 [Com]: FILTER_FLAG_STRIP_HIGH doesn't strip ASCII 127 | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-192257@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=69203&edit=1
ID: 69203
Comment by: whatthejeff@php.net
Reported by: whatthejeff@php.net
Summary: FILTER_FLAG_STRIP_HIGH doesn't strip ASCII 127
Status: Closed
Type: Bug
Package: Filter related
PHP Version: 5.5Git-2015-03-09 (Git)
Assigned To: whatthejeff
Block user comment: N
Private report: N
New Comment:
I guess we should revert this and fix FILTER_FLAG_ENCODE_HIGH if they're not behaving as
intended.
Previous Comments:
------------------------------------------------------------------------
[2015-04-21 11:11:15] whatthejeff@php.net
I think the intended behavior was a little ambiguous since the docs for FILTER_FLAG_ENCODE_HIGH have
been out of sync with the implementation/tests since 5.2.1 (it seems).
------------------------------------------------------------------------
[2015-04-21 10:44:56] derick@php.net
BTW, that's what the docs say too: http://docs.php.net/manual/en/filter.filters.flags.php
------------------------------------------------------------------------
[2015-04-21 08:56:12] derick@php.net
IIRC, they should strip / encode for for >= 128 only.
------------------------------------------------------------------------
[2015-04-21 08:23:59] whatthejeff@php.net
> So it seems like an unintentional side-effect. Until then, both STRIP and ENCODE were for
> >127.
I think there was only one PHP release that included this extension before that commit. Hard to say
if it was intentional or not, but I guess we could ask Derick or Ilia if they remember.
My assumption is that these flags were intended to optionally strip/encode characters that
don't fall within the range of printable ASCII characters (20-7e). It's true that the
original code didn't strip/encode the DEL control character (7f), but I'm not sure if that
was intentional or an oversight.
------------------------------------------------------------------------
[2015-04-20 14:04:45] dominic at mailinator dot com
It looks like FILTER_FLAG_ENCODE_HIGH's behaviour changed in commit: http://git.php.net/?p=php-src.git;a=commit;h=7d7248390cb85f61150304bbdd3eace0a2023a86
with message:
Filter fixes:
Fixed possible double encoding problem with sanitizing filters
Make use of space-strict strip_tags() function
So it seems like an unintentional side-effect. Until then, both STRIP and ENCODE were for >127.
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=69203
--
Edit this bug report at https://bugs.php.net/bug.php?id=69203&edit=1