Bug #68546 [Csd]: json_decode() Fatal error: Cannot access property started with '\0'
| From: | bukka@php.net | Date: | Sun, 21 Jun 2015 14:37:02 +0000 |
| Subject: | Bug #68546 [Csd]: json_decode() Fatal error: Cannot access property started with '\0' | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-193743@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=68546&edit=1
ID: 68546
Updated by: bukka@php.net
Reported by: j dot tvr at centrum dot cz
Summary: json_decode() Fatal error: Cannot access property
started with '\0'
Status: Closed
Type: Bug
Package: JSON related
PHP Version: 5.6.3
Assigned To: bukka
Block user comment: N
Private report: N
New Comment:
FYI: I decided to go for JSON_ERROR_INVALID_PROPERTY_NAME as suggested by Christoph in internals
discussion. It's a better name for the error IMHO.
Previous Comments:
------------------------------------------------------------------------
[2015-06-21 14:32:42] bukka@php.net
Automatic comment on behalf of bukka
Revision: http://git.php.net/?p=php-src.git;a=commit;h=f3df3df8737ace9f4431416fdd0d312cb0ee9cfd
Log: Fix bug #68546 (json_decode cannot access property started with \0)
------------------------------------------------------------------------
[2015-05-28 18:54:50] bukka@php.net
I just emailed about this on internals. The problem is the fatal error and I would like to introduce
a new error called JSON_ERROR_MANGLED_PROPERTY_NAME
------------------------------------------------------------------------
[2015-05-28 06:07:19] yohgaki@php.net
Just an additional comment on this.
PostgreSQL even made "\0" a invalid/unacceptable character for JSONB type.
http://www.postgresql.org/docs/9.4/static/datatype-json.html
PHP has rules on variable names. It's good to enforce the rule to JSON data parsed by
PHP's standard JSON library. IMHO.
------------------------------------------------------------------------
[2015-05-28 00:55:31] cmb@php.net
There are worse things possible than a fatal error if arbitrary
user input is passed to inappropriate functions. Then again, it
doesn't seem to be hard to check for this particular condition and
to return NULL (what is the customary error return value for
json_decode) and to set the error state to JSON_ERROR_CTRL_CHAR (a
new constant might be more approriate), so that it can be
retrieved with json_last_error. I've attached a respective patch
for PHP 5 (PHP 7 would have to be catered to differently).
------------------------------------------------------------------------
[2015-05-28 00:54:08] cmb@php.net
The following patch has been added/updated:
Patch Name: json-0
Revision: 1432774448
URL: https://bugs.php.net/patch-display.php?bug=68546&patch=json-0&revision=1432774448
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=68546
--
Edit this bug report at https://bugs.php.net/bug.php?id=68546&edit=1