Bug #67311 [Opn->Nab]: FILTER_VALIDATE_IP bug with array reference
| From: | cmb@php.net | Date: | Thu, 28 May 2015 14:01:50 +0000 |
| Subject: | Bug #67311 [Opn->Nab]: FILTER_VALIDATE_IP bug with array reference | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-192972@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=67311&edit=1
ID: 67311
Updated by: cmb@php.net
Reported by: bug_34 at hotmaill dot com
Summary: FILTER_VALIDATE_IP bug with array reference
-Status: Open
+Status: Not a bug
Type: Bug
Package: Filter related
Operating System: Windows XP
PHP Version: Irrelevant
-Assigned To:
+Assigned To: cmb
Block user comment: N
Private report: N
New Comment:
Well, the value of the "flags" element is supposed to be an
integer, not an array. The following works as expected:
var_dump(filter_var(
'127.0.0.1',
FILTER_VALIDATE_IP,
array('flags' => FILTER_FLAG_IPV6 | FILTER_FLAG_NO_PRIV_RANGE)
));
// => bool(false)
When a non-empty array is passed as value of the "flags" element,
this is converted to 1 according to PHP's type juggling. 1,
however, is (currently) the value of FILTER_FLAG_ALLOW_OCTAL,
which is ignored for FILTER_VALIDATE_IP, so the result is
basically identical to not passing any $options argument to
filter_var().
Also compare that your "working"
var_dump(filter_var(
'127.0.0.1',
FILTER_VALIDATE_IP,
array('flags' => array(
FILTER_FLAG_IPV4,
FILTER_FLAG_NO_PRIV_RANGE,
FILTER_FLAG_NO_RES_RANGE
))
));
// => string(9) "127.0.0.1"
with the correct
var_dump(filter_var(
'127.0.0.1',
FILTER_VALIDATE_IP,
array('flags' => FILTER_FLAG_IPV4 |
FILTER_FLAG_NO_PRIV_RANGE |
FILTER_FLAG_NO_RES_RANGE)
));
// => bool(false)
Previous Comments:
------------------------------------------------------------------------
[2014-05-20 14:01:51] bug_34 at hotmaill dot com
Description:
------------
FILTER_VALIDATE_IP is not working as expected. Please see code snippet.
PHP version: 5.4.16
OS: Windows XP
Works:
if (filter_var($ip, FILTER_VALIDATE_IP, array('flags' => array(FILTER_FLAG_IPV4,
FILTER_FLAG_NO_PRIV_RANGE, FILTER_FLAG_NO_RES_RANGE))) !== false) {
Does not work:
if (filter_var($ip, FILTER_VALIDATE_IP, array('flags' => array(FILTER_FLAG_IPV6,
FILTER_FLAG_NO_PRIV_RANGE))) !== false) {
Works:
if (filter_var($ip, FILTER_VALIDATE_IP, FILTER_FLAG_IPV6 | FILTER_FLAG_NO_PRIV_RANGE) !== false) {
I didn't test it on different OS and PHP versions.
Test script:
---------------
<?php
function is_ip($ip, $version = null) {
switch ($version) {
case 4:
if (filter_var($ip, FILTER_VALIDATE_IP, array('flags' => array(FILTER_FLAG_IPV4,
FILTER_FLAG_NO_PRIV_RANGE, FILTER_FLAG_NO_RES_RANGE))) !== false) {
return "passed <br />\n";
}
break;
case 6:
if (filter_var($ip, FILTER_VALIDATE_IP, FILTER_FLAG_IPV6) !== false) {
return "passed <br />\n";
}
break;
case 'bug':
if (filter_var($ip, FILTER_VALIDATE_IP, array('flags' => array(FILTER_FLAG_IPV6,
FILTER_FLAG_NO_PRIV_RANGE))) !== false) {
return "passed <br />\n";
}
default:
if (filter_var($ip, FILTER_VALIDATE_IP, array('flags' => array(FILTER_FLAG_IPV4,
FILTER_FLAG_IPV6, FILTER_FLAG_NO_PRIV_RANGE, FILTER_FLAG_NO_RES_RANGE))) !== false) {
return "passed <br />\n";
}
break;
}
return "didn't pass <br />\n";
}
$ip = "127.0.0.1";
echo "IP address validation test: " . $ip . "<br />\n";
echo "v4: ". is_ip($ip, 4);
echo "v6: ". is_ip($ip, 6);
echo "v6: ". is_ip($ip, 'bug');
echo "v4 or v6: ". is_ip($ip);
Expected result:
----------------
The expected result:
IP address validation test: 127.0.0.1
v4: passed
v6: didn't pass
v6: didn't pass
v4 or v6: passed
Actual result:
--------------
The actual result:
IP address validation test: 127.0.0.1
v4: passed
v6: didn't pass
v6: passed
v4 or v6: passed
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=67311&edit=1