Req #71231 [Com]: parse_url doesn't urldecode urlencoded characters

From: Date: Mon, 01 Feb 2016 16:29:56 +0000
Subject: Req #71231 [Com]: parse_url doesn't urldecode urlencoded characters
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-198992@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=71231&edit=1

 ID:                 71231
 Comment by:         willfitch@php.net
 Reported by:        zelnaga at gmail dot com
 Summary:            parse_url doesn't urldecode urlencoded characters
 Status:             Open
 Type:               Feature/Change Request
 Package:            URL related
 Operating System:   Windows 7
 PHP Version:        7.0.1
 Block user comment: N
 Private report:     N

 New Comment:

@yohgaki - I completely agree it would result in unexpected behaviors for previous versions, but
this is a bug.  The path is never decoded - and that isn't double decoding.  Decoding the
path/file AND query parameters should be the expected behavior.  It is for pretty much every other
language as well.

For the BC concern, this would be addressing a bug, so I don't agree that we'd
"break" backwards compatibility - but rather fix it.


Previous Comments:
------------------------------------------------------------------------
[2016-01-15 08:07:33] simonsimcity at gmail dot com

I don't think it should be decoded at that level here.
Think of requests like the following:

var_dump(parse_url("/?foo=ab%26bar%3Dfoo"));
var_dump(parse_url(urldecode("/?foo=ab%26bar%3Dfoo")));

var_dump(parse_url("/foo%2Fab/bar"));
var_dump(parse_url(urldecode("/foo%2Fab/bar")));

I guess the last one is negligible, but I could well see the first example ...

------------------------------------------------------------------------
[2015-12-29 04:16:30] zelnaga at gmail dot com

Double decoding would be a BC breaking change but none-the-less I believe it's the correct
behavior to decode. If you make an HTTP request to that URL Google's webserver decodes it as
/search?q=test .

Like if you do /search?q=te%28st you'd get q=te%28st in the query part of the array but I
believe it should be q=te#st because that's what the web server wold see with
$_GET['q'] - not te%28st.

------------------------------------------------------------------------
[2015-12-28 20:50:37] yohgaki@php.net

If anyone care to implement decoding feature, please _never_ decode by default, since
double(multiple) decoding is a cause of security issues.

------------------------------------------------------------------------
[2015-12-28 20:47:30] yohgaki@php.net

This is not a bug.

------------------------------------------------------------------------
[2015-12-28 19:31:07] zelnaga at gmail dot com

Description:
------------
If you urlencode a character in a URL than the parsed version of that URL ought to contain that
character urldecoded in the output.

Test script:
---------------
<?php
$a = parse_url('https://www.google.com/se%61rch?q=test');

print_r($a);

Expected result:
----------------
Array
(
    [scheme] => https
    [host] => www.google.com
    [path] => /search
    [query] => q=test
)

Actual result:
--------------
Array
(
    [scheme] => https
    [host] => www.google.com
    [path] => /se%61rch
    [query] => q=test
)


------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=71231&edit=1


Thread (7 messages)

« previous php.bugs (#198992) next »