Bug #70298 [Com]: filter_var strips '/' characters, counter to docs

From: Date: Wed, 19 Aug 2015 13:18:14 +0000
Subject: Bug #70298 [Com]: filter_var strips '/' characters, counter to docs
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-195335@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=70298&edit=1 ID: 70298 Comment by: rfredlund13 at gmail dot com Reported by: rfredlund13 at gmail dot com Summary: filter_var strips '/' characters, counter to docs Status: Verified Type: Bug Package: Filter related Operating System: Irrelevant PHP Version: 5.6.12 Block user comment: N Private report: N New Comment: That makes sense. The RFCs are pretty complicated, and cover a lot of edge cases. I do not need to perfectly conform to the RFCs, so I will just remove '/' from my test case. Still, the documentation should be updated to remove '/' from the list of allowed characters. Previous Comments: ------------------------------------------------------------------------ [2015-08-19 13:08:27] cmb@php.net Indeed, slashes are allowed in quoted-strings. However, the slashes had been disallowed as resolution for bug #49470. Not sure, what to do. Actually, the implementation of FILTER_SANITIZE_EMAIL is way too simplistic to even vagely conform to one of the relevant RFCs. Something like Damian's regex-email.php algorithm seems to be more appropriate. ------------------------------------------------------------------------ [2015-08-19 03:15:28] requinix@php.net https://github.com/php/php-src/blob/4a2e40b/ext/filter/sanitizing_filters.c#L307 Both RFCs 822 (which the code mentions) and 5322 (which obsoletes 2822, which obsoletes 822) allow slash. Code I wrote a while back to generate a regex, for reference: https://gist.github.com/requinix/68f2810b8a9824239c23 ------------------------------------------------------------------------ [2015-08-19 02:35:58] rfredlund13 at gmail dot com Description: ------------ I was writing unit tests (using PHPUnit) to validate my email validation functionality, which simply returned the result of filter_var($var, FILTER_SANITIZE_EMAIL). I tested all of the characters allowed in the documentation, but the / character was stripped out. I expected / to be a valid character. This is what the documentation states: FILTER_SANITIZE_EMAIL | Remove all characters except letters, digits and !#$%&'*+-/=?^_`{|}~@.[]. Found at http://php.net/manual/en/filter.filters.sanitize.php I then verified that this problem exists in the latest windows version as well (ran from command line with -r flag). This is either a problem with the implementation of the function, or inaccurate documentation. I briefly tried to interpret RFC 5321/RFC5322, but couldn't find this particular case. Test script: --------------- <?php echo "Output: " . filter_var('!#$%&\'*+-=?^_`{|}~@.[]', FILTER_SANITIZE_EMAIL); echo "\nOutput: " . filter_var('!#$%&\'*+-=?^_`{|}~@.[]/', FILTER_SANITIZE_EMAIL); echo "\nOutput: " . filter_var('/', FILTER_SANITIZE_EMAIL); ?> Expected result: ---------------- Output: !#$%&'*+-=?^_`{|}~@.[] Output: !#$%&'*+-=?^_`{|}~@.[]/ Output: / Actual result: -------------- Output: !#$%&'*+-=?^_`{|}~@.[] Output: !#$%&'*+-=?^_`{|}~@.[] Output: ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=70298&edit=1

« previous php.bugs (#195335) next »