Bug #69982 [Com]: PHP 5.6 populates $_POST with "invalid" data

From: Date: Fri, 03 Jul 2015 02:50:05 +0000
Subject: Bug #69982 [Com]: PHP 5.6 populates $_POST with "invalid" data
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-194094@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=69982&edit=1

 ID:                 69982
 Comment by:         barry at yourang dot org
 Reported by:        barry at yourang dot org
 Summary:            PHP 5.6 populates $_POST with "invalid" data
 Status:             Open
 Type:               Bug
 Package:            Unknown/Other Function
 Operating System:   Linux
 PHP Version:        5.6.10
 Block user comment: N
 Private report:     N

 New Comment:

I am not sure if the new behavior is correct or incorrect, but it's definitely different and
seemingly not mentioned in the documentation. A more real-world example is POSTing JSON using the
wrong Content-Type header (apparently clients do this).  In PHP <= 5.6.0 you would end up with an
empty $_POST, now you have this: 

curl --data '{ "key": "value" }' http://viper-7.com/h0PMyx/5.6.10/
array(1) {
  ["{_"key":_"value"_}"]=>
  string(0) ""
}

This is different than what you have if the correct "Content-Type: application/json"
header is set in the request:

curl -H "Content-Type: application/json" --data '{ "key": "value"
}' http://viper-7.com/h0PMyx/5.6.10/
array(0) {
}

In older versions of PHP you would end up with empty $_POST in either case.  I think I would
consider this change a regression, but if it's determined that it was intentional, I think the
docs should at least be updated to reflect the new behavior because it's backwards incompatible
if you were expecting $_POST to be empty, etc.


Previous Comments:
------------------------------------------------------------------------
[2015-07-02 20:42:26] requinix@php.net

It changed during the implementation of slim_post_data for 5.6.0, but is this really the wrong
behavior? It's the same way $_GET works...

Looks deliberate: http://git.php.net/?p=php-src.git;a=commitdiff;h=e6084da4735c945cb071c4d9259ea0d702eb77c6;hp=52ff129607a7193cccbc6bdfbf1c1e8586e8d0d2#patch15
(add_post_var explicitly allows "foo&" syntax while old php_std_post_handler code does
not)

------------------------------------------------------------------------
[2015-07-02 20:11:17] barry at yourang dot org

Description:
------------
Prior to PHP 5.6, POSTing "invalid" urlencoded data would result in $_POST being an empty
array. In PHP 5.6, PHP now populates $_POST, which is unexpected.  This change seems backwards
incompatible with previous versions of PHP and nothing is mentioned in the documentation that I can
find. 

Test script:
---------------
Both of these URLs just do: 

<?php
var_dump($_POST);


PHP 5.5.24

$ curl http://viper-7.com/hOubxq/5.5.24/ --data
'key'
array(0) {
}

PHP 5.6.10

$ curl http://viper-7.com/h0PMyx/5.6.10/ --data
'key'
array(1) {
  ["key"]=>
  string(0) ""
}

Expected result:
----------------
I would expect the POST request to result in an empty $_POST array in 5.6 just like 5.5

Actual result:
--------------
$_POST is populated with data.


------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=69982&edit=1


Thread (3 messages)

« previous php.bugs (#194094) next »