Bug #55200 [Opn->Ver]: str_getcsv parses lines incorrectly
| From: | cmb@php.net | Date: | Tue, 19 May 2015 13:27:02 +0000 |
| Subject: | Bug #55200 [Opn->Ver]: str_getcsv parses lines incorrectly | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-192762@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=55200&edit=1
ID: 55200
Updated by: cmb@php.net
Reported by: dmitry dot dulepov at gmail dot com
Summary: str_getcsv parses lines incorrectly
-Status: Open
+Status: Verified
Type: Bug
-Package: Unknown/Other Function
+Package: Strings related
PHP Version: 5.3.6
Block user comment: N
Private report: N
New Comment:
The given test input is not valid according to RFC 4180;
whitespace is not allowed between 'COMMA' and 'escaped'. However,
the current behavior of str_getcsv() doesn't make sense to me, see
<http://3v4l.org/roJnp> and <http://3v4l.org/XcrLG>. Returning
FALSE or at least giving a warning or notice for such input seems
to be more appropriate.
By the way, fgetcsv() shows the same behavior.
Previous Comments:
------------------------------------------------------------------------
[2011-07-29 05:42:34] dmitry dot dulepov at gmail dot com
It is not about input validation :) Your example is clearly invalid input. The
function should fail and return FALSE. My example perfectly fits into formal CSV
grammar, thus it is valid input. It is just parsed incorrectly.
I would not send you a bug about invalid input :)
------------------------------------------------------------------------
[2011-07-29 01:44:30] lonnyk at gmail dot com
str_getcsv is a conversion tool and not an input validator. Any invalid input is
surely not going to work correctly and I do not think it is good practice to
account for bad input b/c it would cause extra processing time when it is not
needed.
If the input were:
var_dump(str_getcsv('"123" a , "456" ', ',',
'"'))
what would you expect str_getcsv to do?
------------------------------------------------------------------------
[2011-07-13 09:10:16] dmitry dot dulepov at gmail dot com
Description:
------------
Putting a space around the separator *and* using quotes around fields adds
spaces to the field. The following line:
"123" , "456"
should produce:
"123" and "456"
but it makes:
"123 " and " 456".
In the RFC4180 the specification suggests that if the field contains quotes,
only the text inside quotes is the content of the field. Here is the formal
gramma:
record = field *(COMMA field)
field = (escaped / non-escaped)
escaped = DQUOTE *(TEXTDATA / COMMA / CR / LF / 2DQUOTE) DQUOTE
non-escaped = *TEXTDATA
Thus spaces should appear in field only if the field is not quoted.
Test script:
---------------
print_r(str_getcsv('"123" , "456" ', ',',
'"'))
Expected result:
----------------
array(
0 => "123",
1 => "456",
)
Actual result:
--------------
array(
0 => "123 ",
1 => "456 ",
)
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=55200&edit=1